Privacy Policy of the NianiaLog Application
Effective date: 18.06.2026
Document version: 1
1. General information
-
This Privacy Policy describes the rules for processing personal data in connection with the use of the NianiaLog application.
-
The controller of personal data is Paweł Borkowski conducting business under the name Paweł Borkowski BrainHatchery, ul. Jemiołowa 44/107a, 53-426 Wrocław, Lower Silesian Voivodeship, NIP: 6151878784, REGON: 367951024.
-
Contact with the Controller:
- for matters related to the NianiaLog application and data protection: kontakt@nianialog.pl,
- general company contact: kontakt@brainhatchery.com.
-
The Controller has not appointed a data protection officer.
-
The application has been designed in accordance with the principle of data minimisation. This means that the application does not require providing data that is not necessary for its operation.
2. Key privacy principles
-
The application does not require providing a phone number.
-
The application does not require providing a residential address.
-
The application does not require providing a PESEL number.
-
The application does not store photos or documents.
-
The application does not include a chat function.
-
A child may be identified by a pseudonym, shortened first name or another name chosen by the parent.
-
The User should not enter into the application medical data, diagnoses, test results, medical documentation or other information that the application does not require.
3. What data we process
In connection with the use of the application, the Controller may process the following categories of data:
-
User account data:
- e-mail address,
- account identifier,
- display name or first name provided by the User,
- information about the role in the family, e.g. parent, second parent, nanny.
-
Family data:
- family name,
- information about family members in the application,
- information about invitations to the family,
- activity statuses of family members.
-
Child data:
- first name, pseudonym or other designation of the child,
- date of birth, if provided in the application,
- settings related to feeding.
-
Daily entries:
- milk and amount of milk,
- breastfeeding,
- meals,
- naps,
- poops,
- notes entered by Users.
-
Data concerning the nanny’s work:
- planned working days,
- logged working hours,
- breaks,
- days off,
- approval statuses of hours,
- monthly or hourly settlements,
- nanny’s duties and their approval status.
-
Technical data:
- technical identifiers of accounts and records,
- creation and update dates of entries,
- information needed for login, sessions and security,
- basic technical logs of infrastructure providers, if generated.
4. Data that the application does not require
-
The application does not require and is not intended for storing:
- PESEL number,
- residential address,
- phone number,
- photos,
- documents,
- medical documentation,
- diagnoses,
- test results,
- copies of contracts,
- bank details.
-
If the User nevertheless enters such data in a text field, they do so on their own initiative. The Controller may request the removal of such data or remove it if this is necessary for security or legal compliance.
5. Purposes and legal bases of processing
The Controller processes personal data for the following purposes:
-
Creating and handling a User account:
- purpose: registration, login, User identification, session handling,
- legal basis: performance of an agreement for the provision of electronic services or taking steps prior to entering into such an agreement.
-
Providing the NianiaLog service:
- purpose: enabling the management of a family, daily entries, working hours, settlements and duties,
- legal basis: performance of an agreement for the provision of electronic services.
-
Handling invitations to a family:
- purpose: enabling the parent to invite a second parent and a nanny,
- legal basis: performance of an agreement for the provision of electronic services.
-
Handling account and data deletion:
- purpose: fulfilling a request to delete an account, deactivating access, anonymising or deleting data,
- legal basis: performance of an agreement, legal obligation or the Controller’s legitimate interest consisting in ensuring data consistency and security.
-
Application security:
- purpose: preventing abuse, detecting errors, protecting data, ensuring system integrity,
- legal basis: the Controller’s legitimate interest.
-
Contact and handling reports:
- purpose: responding to messages, complaints, questions and reports,
- legal basis: performance of an agreement, legal obligation or the Controller’s legitimate interest.
-
Fulfilling legal obligations:
- purpose: fulfilling obligations arising from legal provisions, including handling requests concerning personal data,
- legal basis: a legal obligation imposed on the Controller.
-
Defence or pursuit of claims:
- purpose: establishing, pursuing or defending against claims,
- legal basis: the Controller’s legitimate interest.
6. Child data
-
Data concerning a child is entered into the application by a parent or another person authorised by the parent.
-
The parent decides what designation of the child will be used in the application. It may be a first name, pseudonym or another name.
-
The Controller recommends using the minimum scope of child data.
-
The application does not require providing full identifying data of a child.
-
The application is not intended for storing a child’s medical documentation or special information about health.
-
Entries such as feeding, nap, meal or poop are used for the ongoing organisation of care and communication between the parent and the nanny.
-
If a parent or nanny enters information in notes that goes beyond the ordinary organisation of care, they do so at their own responsibility. The Controller recommends not entering sensitive data or medical information.
7. Who has access to data in the application
-
Access to family data is granted to Users assigned to that family according to their role:
- parent or family owner,
- second parent,
- nanny.
-
A parent may view and manage family data within the scope made available in the application.
-
The nanny has access to data necessary to perform her role in the family, in particular daily entries, working hours, settlements and duties, taking privacy settings into account.
-
The application may limit the visibility of some data, e.g. information about breastfeeding, in accordance with the parent’s settings.
-
The User does not have access to data of other families to which they have not been invited.
8. Data recipients and service providers
-
Data may be entrusted to technical service providers who help maintain the application.
-
In particular, the Controller uses:
- Supabase – backend infrastructure, database, authentication and server functions,
- Firebase / Google – hosting of the web/PWA application,
- e-mail or domain hosting provider – handling e-mail messages, in particular login codes and technical messages,
- other providers of technical tools, if they are necessary to maintain the application.
-
Providers process data on the basis of appropriate agreements or terms of service.
-
Providers may use subcontractors in accordance with their rules and agreements.
-
Data may be processed in the European Economic Area or outside it if the use of a given provider results in this. In such a case, data transfer takes place on the basis of appropriate legal mechanisms, such as standard contractual clauses or other solutions provided for by the GDPR.
9. Data retention period
-
Account data is stored for the period during which the account is used.
-
Family data, daily entries, working hours, settlements and duties are stored for the period of the family’s existence in the application or until their deletion in accordance with the functions of the application.
-
If the User deletes a nanny or second parent account, historical data related to the family may remain in the application in anonymised form or assigned to the deleted account, if this is necessary to preserve the history of the family, hours, settlements or duties.
-
If the only parent who is the owner of the family deletes the account, family data may be deleted together with the account.
-
Data related to complaints, contact or claims may be stored for the period necessary to handle the matter and until the expiry of limitation periods for claims.
-
Technical data and logs may be stored for the period necessary to ensure the security, operation and diagnostics of the application.
-
Data may be stored longer if such an obligation arises from legal provisions.
10. Account and data deletion
-
The User may delete their account independently in the application.
-
Deleting a nanny account results in deletion or deactivation of her access to the families in which she participated. It does not automatically delete families or parents’ historical data.
-
Deleting a second parent’s account results in deletion or deactivation of that person’s access to the family. The family remains available to the family owner.
-
If the account is deleted by the family owner and there is an active second parent, the second parent may become the owner of the family and the family data remains in the application.
-
If the account is deleted by the only parent who is the family owner, deleting the account may result in deletion of the family and all its data.
-
Account deletion is irreversible with respect to data deleted from the active database of the application.
-
For matters concerning data deletion, technical problems with account deletion or other requests concerning data, contact may be made at kontakt@nianialog.pl.
11. Rights of data subjects
A data subject has the rights specified in the GDPR, in particular:
- the right of access to data,
- the right to rectification of data,
- the right to erasure of data,
- the right to restriction of processing,
- the right to data portability,
- the right to object to data processing,
- the right to withdraw consent if data is processed on the basis of consent,
- the right to lodge a complaint with the President of the Personal Data Protection Office.
To exercise the rights, contact may be made with the Controller at: kontakt@nianialog.pl.
12. Complaint to the supervisory authority
-
A data subject may lodge a complaint with the President of the Personal Data Protection Office if they believe that the processing of their data violates the GDPR.
-
Contact details and current information on lodging complaints are available on the website of the Personal Data Protection Office.
-
Before lodging a complaint, the Controller may be contacted to clarify the matter.
13. Cookies, local storage and similar technologies
-
The application may use local storage, session storage or similar browser mechanisms for the purpose of:
- maintaining a login session,
- remembering application settings, such as language, theme or the most recently selected nanny,
- proper operation of the PWA application.
-
The application currently does not use marketing cookies or marketing analytics within the application itself.
-
The nianialog.pl website may have a separate cookie policy or privacy policy if it uses analytics, marketing or other tools not directly related to the application.
14. Security
-
The Controller applies technical and organisational measures aimed at protecting personal data against unauthorised access, loss, alteration or destruction.
-
Access to data in the application is limited by User roles and secured by access control mechanisms.
-
The User should protect access to their e-mail address and to the device on which they use the application.
-
The User should immediately inform the Controller of any suspected unauthorised access to the account or data.
15. Automated decision-making and profiling
-
The Controller does not use data from the application for automated decision-making producing legal effects concerning the User.
-
The Controller does not conduct marketing profiling in the application.
16. Changes to the Privacy Policy
-
The Privacy Policy may be updated in the event of changes to application functions, legal provisions, service providers or the manner of data processing.
-
The User will be informed of material changes to the Privacy Policy in the application or through another appropriate channel.
-
If a change requires renewed acceptance, the application may ask the User to accept the new version of the document.
17. Contact
For matters concerning privacy and personal data, contact may be made at:
General company contact: