Guardian Bubble

PRIVACY POLICY

GUARDIAN BUBBLE AND GUARDIAN BUBBLE KIDS

Version: 2.3

Last updated: August 2026

1. WELCOME TO GUARDIAN BUBBLE

At Guardian Bubble we understand that protecting minors and respecting their privacy must always go hand in hand.

We know that installing a parental control application means placing a great deal of trust in the company that develops it. That trust requires us to act with maximum transparency, to explain clearly how the service works, and to guarantee that personal data is processed responsibly, securely and in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”), as well as any applicable national legislation.

Guardian Bubble has been designed following the principles of data protection by design and by default (Privacy by Design & Privacy by Default). This means that, from the earliest stages of development, technical and organisational measures have been adopted to limit the processing of personal data to what is strictly necessary to provide the service, to minimise privacy risks and to guarantee a high level of protection of information.

Our priority is to protect the minor, but also to preserve their privacy, avoiding unnecessary processing and ensuring that the father, mother or legal guardian always remains in control of the features that are activated.

This Privacy Policy clearly and transparently explains:

  • who the data controller is
  • how Guardian Bubble works
  • what personal data we process
  • for what purposes we use that information
  • the legal basis that legitimises each processing operation
  • how long we keep the data
  • who we may share it with
  • what security measures we apply
  • what rights users have and how they can exercise them.

We recommend reading this Policy carefully before using any of the applications that make up Guardian Bubble. If you have any questions, you can contact our Data Protection Officer at any time using the contact details provided at the end of this document.

2. WHO IS THE DATA CONTROLLER?

The controller of the personal data is:

Parental Control Tech OÜ

  • A company incorporated under the laws of the Republic of Estonia.
  • Registration number: 17229634.
  • Contact email address: admin@guardianbubble.com
  • Website: https://www.guardianbubble.com

Parental Control Tech OÜ determines the purposes and means of the processing of personal data arising from the use of Guardian Bubble and Guardian Bubble Kids (displayed as “Bubble Kids” on the minor's device), and is responsible for ensuring that such processing is carried out in accordance with the data protection legislation in force.

Data Protection Officer

In order to guarantee compliance with the applicable legislation and to offer a specialised channel for any privacy-related matter, Parental Control Tech OÜ has appointed a Data Protection Officer (DPO).

Data Protection Officer: Consulting Normativo, S.L.

Email address: dpd@consultingnormativo.es

You may contact the Data Protection Officer to:

  • raise queries about the processing of your personal data
  • exercise any of the rights recognised by the GDPR
  • report privacy-related incidents
  • raise any question about how Guardian Bubble works from a data protection perspective.

The Data Protection Officer acts with full independence in the exercise of their functions, in accordance with Articles 37 to 39 of Regulation (EU) 2016/679.

Competent supervisory authority

Parental Control Tech OÜ has its main establishment in Estonia and provides its services in different Member States of the European Union. The determination of the competent lead supervisory authority will be made in accordance with Articles 55 and 56 of Regulation (EU) 2016/679, taking into account the main establishment of the controller and the characteristics of the cross-border processing carried out.

This is without prejudice to the right of any data subject to lodge a complaint with the supervisory authority of their place of habitual residence, place of work or the place where they consider that a possible infringement of data protection legislation has occurred, under the terms set out in Article 77 of the GDPR.

3. WHO IS GUARDIAN BUBBLE FOR?

Guardian Bubble is a parental protection service designed to be used exclusively by fathers, mothers or legal guardians who wish to have technological tools to protect the physical and digital safety of the minors under their responsibility.

The service is not directed at minors as contracting users, nor does it allow them to create an account, take out a subscription or autonomously manage the main features of the application.

Contracting the service, paying for the subscription, the initial set-up, activating the different parental protection features and managing the account are always the responsibility of the adult in charge.

For its part, the application installed on the minor's device (Guardian Bubble Kids) is a technical component necessary for the operation of the service, but it cannot be used independently or access the administration features reserved for the father, mother or legal guardian.

The design of Guardian Bubble responds to the principle of the best interests of the child, seeking to maintain a balance between their protection, respect for their privacy and the responsible exercise of parental authority or guardianship by the adult.

4. HOW DOES GUARDIAN BUBBLE WORK?

Guardian Bubble is a parental protection service made up of different mobile applications developed to run on devices with Android and iOS operating systems.

In order to adapt to the technical characteristics of each platform, the service is distributed through four separate applications which together make up a single parental protection system:

ApplicationIntended userOperating system
Guardian BubbleFather, mother or legal guardianAndroid
Guardian BubbleFather, mother or legal guardianiOS
Guardian Bubble KidsMinorAndroid
Guardian Bubble KidsMinoriOS

Although there are four different applications for technical reasons, they all form part of a single service and operate in a coordinated manner through a secure pairing process between the device of the responsible adult and the device of the minor.

The Guardian Bubble application is the administration platform of the service and allows the father, mother or legal guardian to manage the parental protection features.

The Guardian Bubble Kids application, installed on the minor's device, performs the functions necessary to provide the contracted service and transmits the strictly necessary information to the device of the responsible adult.

The Guardian Bubble Kids application is displayed on the minor's device under the abbreviated name “Bubble Kids”. Both names refer to the same application.

Guardian Bubble is not designed to run covertly or to hide its presence on the minor's device. The installation of the application is visible, and the service has been conceived as a tool for protection and digital accompaniment, not as a system of secret surveillance.

4.1. Creating the account

To start using Guardian Bubble, the father, mother or legal guardian must create a personal account by providing the data necessary to identify the user and contract the service.

During the registration process, the following data, among others, may be requested:

  • name
  • email address
  • password
  • country of residence
  • language
  • information necessary to manage the subscription where applicable.

Creating the account implies acceptance of the Terms and Conditions of Use and of this Privacy Policy.

Once registration is complete, the user will be able to access the Guardian Bubble configuration panel and manage the different features available.

4.2. Pairing the adult's device with the minor's device

The operation of the service requires pairing the minor's device with the account created by the father, mother or legal guardian.

To do so, the adult installs the Guardian Bubble Kids application on the minor's device.

During the set-up process, the system generates a unique pairing code, which must be entered in the Guardian Bubble application installed on the adult's device.

This procedure makes it possible to verify that both devices belong to the same family unit and prevents accidental or unauthorised pairings.

Pairing can only be carried out by the father, mother or legal guardian who administers the account.

4.3. Configuring the features

Once both devices are paired, the responsible adult can decide which features to activate.

Among other things, Guardian Bubble allows you to:

  • view the minor's location
  • receive notifications when the minor arrives at or leaves previously configured zones
  • consult the history of journeys made during the day
  • configure safe zones or zones requiring special attention
  • set device usage schedules
  • limit the maximum usage time of certain applications
  • temporarily block access to the device during certain time periods
  • receive alerts related to possible risk situations detected by means of Artificial Intelligence (Android)
  • receive SOS alerts sent by the minor
  • send an audible signal to the minor's device to help locate it.

Each of these features can be activated, modified or deactivated from the Guardian Bubble application.

The responsible adult retains control over the configuration of the service at all times.

4.4. Differences between Android and iOS

Certain features may vary depending on the operating system used.

These differences are exclusively due to the technical limitations and operating policies established by Google (Android) and Apple (iOS).

In particular:

  • some parental control functions require specific permissions available only on Android
  • screen-time limitation options may vary between the two operating systems
  • certain automated analysis features using Artificial Intelligence are currently only available on Android devices
  • supervision capabilities may be limited by the restrictions imposed by Apple to protect the security and privacy of its devices.

Guardian Bubble informs users of these differences before contracting where they may significantly affect the operation of the service.

4.5. Purpose of the service

Guardian Bubble has been developed with a single purpose: to provide fathers, mothers and legal guardians with technological tools that allow them to protect the physical and digital safety of the minors under their responsibility.

Under no circumstances has the application been designed to:

  • indiscriminately monitor the minor's private life
  • carry out secret surveillance activities
  • build commercial profiles
  • sell personal information
  • display personalised advertising based on the minor's activity.

The processing of personal data is strictly limited to the purposes described in this Privacy Policy and to the provision of the service contracted by the responsible adult.

5. WHAT PERSONAL DATA DO WE PROCESS?

Guardian Bubble processes only the personal data that is necessary to provide the parental protection service requested by the father, mother or legal guardian.

The data processed varies depending on the features activated by the user, the operating system of the device and the configuration made by the responsible adult.

Under no circumstances is more data requested or processed than is strictly necessary for the provision of the service, applying at all times the data minimisation principle set out in Article 5(1)(c) of Regulation (EU) 2016/679.

The main categories of data processed are as follows.

5.1. Identification data of the father, mother or legal guardian

To manage the user account and provide the service, Guardian Bubble processes the following data of the responsible adult:

  • first name and surname (where provided)
  • email address
  • password (stored in encrypted form)
  • internal user identifier
  • selected language
  • country of residence
  • information related to the contracted subscription
  • technical identifiers necessary for the operation of the application.

This data makes it possible to identify the account holder, manage the contracting of the service, authenticate access and administer the different features available.

5.2. Data relating to the minor

The application processes certain data relating to the minor exclusively to enable the operation of the service contracted by the father, mother or legal guardian.

This may include:

  • name or alias assigned by the responsible adult
  • internal device identifier
  • family unit identifier
  • configuration assigned by the parent
  • application operating parameters.

Guardian Bubble does not ask the minor to create an independent account or to contract the service.

5.3. Location data

When the father, mother or legal guardian activates this feature, Guardian Bubble processes information relating to the location of the minor's device.

The location information processed may be precise, with an accuracy of a few metres, depending on the capabilities of the device, the permissions granted and coverage conditions. Location accuracy is necessary for the correct operation of safe zones, entry and exit alerts and the SOS function.

This may include:

  • device location
  • location history corresponding to the journeys made during the day
  • entry into and exit from zones configured by the responsible adult
  • generation of alerts when the minor enters or leaves those zones.

Location information is used exclusively to provide the parental protection features requested by the user and is not used for advertising, commercial or profiling purposes.

5.4. Information on device usage

Depending on the operating system and the features activated, Guardian Bubble may process information relating to the minor's use of the device.

Among other data, the following may be processed:

  • applications used
  • usage time of each application
  • time slots of use
  • use of applications subject to parental control
  • compliance with the time limits set by the responsible adult.

This information allows the father, mother or legal guardian to configure usage limits and to know the approximate usage time of the device.

5.5. Protection features using Artificial Intelligence (Android only)

On Android devices, and only when the father, mother or legal guardian expressly activates this feature, Guardian Bubble may temporarily analyse certain content displayed in compatible applications for the sole purpose of detecting possible risk situations for the minor.

This processing incorporates specific measures designed to guarantee the protection of personal data, including the minimisation of the information processed, the deletion of the content once the analysis is completed and the absence of retention of the screenshots used to carry out that analysis.

A detailed description of how these features work, of the categories analysed and of the applicable safeguards can be found in section 8 of this Privacy Policy.

5.6. Data related to the SOS function

When the minor uses the SOS function, Guardian Bubble processes only the information necessary to transmit the alert to the father, mother or legal guardian.

This may include:

  • identification of the device that triggers the alert
  • date and time of activation
  • location at the time of sending
  • establishment of the audio communication where this feature is available.

The purpose of this processing is to enable a rapid response to possible emergency situations.

5.7. Technical data of the device

In order to guarantee the correct operation of the service, Guardian Bubble processes certain technical data of the device, including:

  • device model
  • operating system version
  • technical identifiers of the application
  • operating logs
  • information necessary to detect errors and technical incidents
  • identifiers associated with push notifications.

This data is used exclusively to maintain the security, stability and correct operation of the platform.

5.8. Data derived from the subscription

When the user contracts a subscription, Guardian Bubble may process information related to:

  • the type of subscription contracted
  • licence status
  • renewals
  • cancellations
  • identifiers provided by Apple App Store or Google Play
  • verifications carried out by RevenueCat.

Guardian Bubble does not store full bank card details and does not access the means of payment used by the user.

The financial management of in-app purchases is handled by Apple App Store or Google Play, depending on the operating system used.

5.9. Emergency contacts

When the father, mother or legal guardian configures the emergency features (SOS and priority calls), Guardian Bubble processes the data of the emergency contacts that the responsible adult expressly selects: name and telephone number.

These contacts may correspond to persons who are not users of Guardian Bubble. Their processing is limited to enabling notification or communication in emergency situations configured by the responsible adult, on the basis of the legitimate interest in the protection of the minor (Article 6(1)(f) GDPR), balanced in accordance with the best interests of the child, and of the performance of the contracted service with respect to the responsible adult (Article 6(1)(b) GDPR).

Guardian Bubble does not access the rest of the device's address book and does not keep any contacts other than those expressly selected. Emergency contacts are kept for as long as the responsible adult keeps them configured and are deleted when the adult removes them or when the account is deleted.

5.10. Data we do not process

In the interests of transparency, it is equally important to explain what information Guardian Bubble does not process.

As a general rule:

  • we do not store the minor's complete conversations
  • we do not keep the screenshots used during the analysis carried out by means of Artificial Intelligence
  • we do not make continuous recordings of the device's activity
  • we do not permanently listen to the device's microphone
  • we do not access the content of telephone calls
  • we do not use personal data to display personalised advertising
  • we do not sell personal data to third parties
  • we do not use the analysed content to train Artificial Intelligence models.

These limitations form part of the design of the service and respond to the principles of data minimisation, purpose limitation and data protection by design set out in Regulation (EU) 2016/679.

6. FOR WHAT PURPOSES AND ON WHAT LEGAL BASIS DO WE PROCESS YOUR DATA?

Guardian Bubble processes personal data only for the purposes described in this Privacy Policy and always on the basis of one of the lawful grounds set out in Article 6 of Regulation (EU) 2016/679.

Each processing operation responds to a specific purpose, and the data will not be used for purposes incompatible with those for which it was collected.

In certain cases, processing may rely simultaneously on more than one legal basis where this is necessary for the correct provision of the service or for compliance with legal obligations.

The main processing operations carried out by Guardian Bubble are described below.

6.1. Provision of the parental protection service

Purpose

To manage user registration, keep the account active, pair the devices of the father, mother or legal guardian with the minor's device and enable the general operation of the application.

Data processed

  • Identification data of the responsible adult.
  • Technical data of the device.
  • Identification data of the minor.
  • Account configuration.

Legal basis

Article 6(1)(b) GDPR: performance of the contract entered into with the user. Without this processing it would not be possible to provide the contracted service.

6.2. Subscription management

Purpose

To manage subscriptions, verify licences, control renewals, process cancellations and keep access to the contracted features active.

Data processed

  • User identifiers.
  • Subscription information.
  • Identifiers provided by Apple App Store or Google Play.

Legal basis

Article 6(1)(b) GDPR.

6.3. Geolocation of the minor

Purpose

To allow the father, mother or legal guardian to know the minor's location, configure safe zones or zones requiring special attention and receive alerts when the minor enters or leaves those zones.

Data processed

  • Device location.
  • Journey history.
  • Geofences.
  • Location alerts.

Legal basis

Article 6(1)(b) GDPR, as this is a feature expressly requested by the user through the contracting and configuration of the service. Geolocation is only activated when the responsible adult configures this feature.

6.4. Control of screen time and applications

Purpose

To allow the father, mother or legal guardian to know the device usage time, set usage limits and configure time restrictions.

Data processed

  • Applications used.
  • Usage time.
  • Schedules.
  • Limit configuration.

Legal basis

Article 6(1)(b) GDPR.

6.5. SOS function

Purpose

To allow the minor to send an immediate alert to the father, mother or legal guardian in emergency situations and to enable the communication associated with this feature.

Data processed

  • Device identifier.
  • Date and time.
  • Location.
  • Information necessary to establish the audio communication.

Legal basis

Article 6(1)(b) GDPR. This purpose includes the processing of the data of the emergency contacts expressly selected by the responsible adult, as described in section 5.9 of this Policy.

6.6. Detection of risk situations by means of Artificial Intelligence

Purpose

To temporarily analyse certain content displayed in compatible applications in order to detect possible situations that may compromise the safety or well-being of the minor and to generate an alert addressed exclusively to the father, mother or legal guardian.

Data processed

  • Text displayed on screen.
  • Visual content displayed in compatible applications.
  • Risk category detected.
  • Technical identifiers necessary to associate the alert with the corresponding minor.

Legal basis

Article 6(1)(b) GDPR, as this forms part of the features contracted by the user.

In those exceptional cases in which data belonging to special categories may incidentally appear during the analysis, such processing occurs exclusively because it is technically unavoidable in order to detect the risk situation, and always applying strict measures of minimisation, purpose limitation and immediate deletion of the analysed content.

Guardian Bubble does not use this information to build profiles of the minor, to carry out assessments of their personality or to make automated decisions.

6.7. Platform security

Purpose

To guarantee the security of the application, prevent unauthorised access, detect technical errors, investigate security incidents and protect the integrity of the service.

Data processed

  • Technical logs.
  • Device information.
  • IP addresses where necessary.
  • Security events.

Legal basis

Article 6(1)(f) GDPR. The legitimate interest consists of guaranteeing the security, availability and correct operation of the platform.

6.8. Handling of queries and exercise of rights

Purpose

To manage requests received from users, answer queries and process the exercise of the rights recognised by data protection legislation.

Data processed

  • Identification data.
  • Information contained in the request.
  • Supporting documentation where necessary.

Legal basis

Article 6(1)(c) GDPR, compliance with legal obligations.

6.9. Compliance with legal obligations

Purpose

To comply with the obligations imposed by the applicable legislation, including those arising from data protection, consumer, tax and fraud prevention legislation, or from requests by authorities.

Legal basis

Article 6(1)(c) GDPR.

6.10. Service improvement

Guardian Bubble may use aggregated statistical and technical information to improve the performance, stability and security of the service.

Wherever possible, this information will be processed in aggregated or anonymised form, so that it does not allow users to be identified directly or indirectly.

Under no circumstances will conversations, screenshots or content analysed by means of Artificial Intelligence be used to train AI models or to develop third-party products.

Legal basis

Article 6(1)(f) GDPR, legitimate interest consisting of improving the quality and security of the service.

6.11. Important information on the processing of minors' data

Guardian Bubble has been conceived as a tool to support the responsible exercise of parental authority or legal guardianship.

The minor's data is processed exclusively to provide the features contracted by the father, mother or legal guardian and always under their control.

The minor cannot create an independent account or contract the service.

The available features have been designed applying the principles of data minimisation, protection by design and protection by default, seeking to maintain a balance between the minor's safety and respect for their privacy.

6.12. Automated decisions

Guardian Bubble does not make automated decisions that produce legal effects or significantly affect the minor, within the meaning of Article 22 of Regulation (EU) 2016/679.

The Artificial Intelligence used by the application is limited to detecting possible risk indicators and generating an alert addressed to the father, mother or legal guardian.

The assessment of the situation and any subsequent decision are the exclusive responsibility of the responsible adult.

7. WHAT PERMISSIONS DOES THE APPLICATION REQUIRE?

In order for Guardian Bubble to correctly provide the contracted features, the application may request certain device permissions.

The permissions requested depend on the operating system (Android or iOS), the installed version and the features that the father, mother or legal guardian decides to activate.

Guardian Bubble requests only those permissions strictly necessary for the operation of each feature. Where a permission is not essential for a given feature, it will not be used.

The user may manage the permissions granted at any time from the device settings, although revoking certain permissions may prevent the correct operation of some features of the application.

Permissions used

PermissionPurpose
LocationTo enable the location of the minor's device, display its location (which may be precise, with an accuracy of a few metres, including background location), manage safe zones and generate entry or exit alerts.
Accessibility (Android)To enable the operation of the parental control features, screen-time supervision and risk analysis in compatible applications.
App usage (Android)To obtain information on application usage time so that the father, mother or legal guardian can configure usage limits and schedules.
NotificationsTo send alerts related to the minor's safety, SOS alerts and other communications necessary for the operation of the service.
MicrophoneTo enable the audio communication associated with the SOS feature when activated by the minor.
Network connectivityTo synchronise information between the paired devices and guarantee the correct provision of the service.
Background executionTo keep certain safety functions active, such as geolocation or the receipt of alerts, even when the application is not open.
Contacts (minor's app)To allow the responsible adult to select the emergency contacts (name and telephone number) for the SOS and priority-call features, in accordance with section 5.9. The rest of the address book is not accessed.
Screen content capture (minor's app, Android)To enable the periodic analysis of the content displayed on screen by means of Artificial Intelligence for the detection of possible risk situations, in accordance with section 8.
Local virtual private network (on-device VPN, minor's app)To apply the content and web-domain filtering configured by the responsible adult. Filtering is performed locally on the device; browsing traffic is not diverted to Guardian Bubble's servers or to third parties.
Camera / photo library (adult's app)To allow the responsible adult to set a profile picture.
Call management and redirection (minor's app, Android)To ensure that the minor can make emergency calls at all times, even when the device is locked by means of the Superlock feature. This permission is not used to monitor, record or block calls.

Limitations depending on the operating system

Some features may vary between Android and iOS due to the technical limitations and policies established by Google and Apple. In particular:

  • certain supervision and parental control functions are only available on Android devices
  • on iOS devices, some features may be limited by the restrictions imposed by Apple to protect the security and privacy of the operating system
  • Guardian Bubble automatically adapts its operation to the capabilities permitted by each platform.

In any event, only the permissions necessary for the features actually available on the device in use will be requested.

Managing permissions

The father, mother or legal guardian may modify the permissions granted to Guardian Bubble at any time from the device settings.

However, deactivating certain permissions may prevent the correct operation of some features of the service, such as locating the minor, receiving alerts or detecting certain risk situations.

Guardian Bubble does not use the permissions granted for purposes other than those described in this Privacy Policy.

8. PROTECTION FEATURES USING ARTIFICIAL INTELLIGENCE (ANDROID ONLY)

One of the main features of Guardian Bubble is to help the father, mother or legal guardian to detect, at an early stage, certain situations that may compromise the physical or digital safety of the minor.

For this purpose, the application incorporates an automated analysis system based on Artificial Intelligence, currently available only on Android devices and exclusively when the responsible adult expressly decides to activate it.

This feature is a tool to support parental supervision and in no case replaces the judgement or intervention of the father, mother or legal guardian.

How does it work?

When the feature is activated, the application may temporarily analyse the content displayed in certain compatible applications.

To carry out this analysis, Guardian Bubble takes a screenshot each time the minor opens a monitored application or switches between monitored applications (one capture per event). If the minor continues using the same compatible application, a new capture is taken approximately every five minutes for as long as that use continues.

Captures are not continuous, do not constitute a permanent recording of the device's activity and are only taken in respect of compatible applications while this feature remains activated by the father, mother or legal guardian.

What content may be analysed?

Depending on the feature activated, the system may temporarily analyse:

  • text displayed on screen
  • images or visual content displayed in compatible applications.

The sole purpose of the analysis is to detect possible situations related to:

  • bullying or cyberbullying
  • sexual content or sexting
  • violence
  • drugs or alcohol
  • self-harm
  • suicidal ideation
  • hate speech
  • concealment signals or the use of codes or expressions intended to warn of the presence of adults or to make certain conversations harder to understand
  • other situations which, depending on the context, may represent a risk to the minor.

What happens to that content?

Guardian Bubble applies the data minimisation principle throughout the entire analysis process.

The analysed content:

  • is used exclusively to detect possible risk situations
  • is not used to train Artificial Intelligence models
  • is not incorporated into the technology provider's generative models
  • is not reused to improve third-party products or services
  • is processed only for the time strictly necessary to carry out the analysis
  • is not incorporated into the user's history
  • no copy of the analysed content is kept
  • is sent to the analysis service without being associated with the minor's identity or account identifiers. However, the content displayed on screen may incidentally include names, aliases or other data visible in the conversation or application analysed; such content is analysed ephemerally, is not stored and is deleted once the analysis is completed, and the technology provider does not retain it or use it for other purposes
  • if a capture cannot be sent at the time it is generated due to a lack of connectivity, it is kept temporarily on the device itself, in encrypted form and without being transmitted, only until it can be sent and, in any event, for a maximum of 72 hours. Such temporary copies are likewise deleted when supervision is deactivated, when the session is closed or when the device is unpaired.

Once the analysis is completed, the content used during that process is deleted and does not remain stored.

The analysis is carried out using Google Vertex AI, configured in the europe-west4 region (Netherlands), with the Zero Data Retention feature, so that the technology provider does not retain the processed content or use it to train Artificial Intelligence models.

What does the father, mother or legal guardian receive?

The responsible adult does not receive the conversations, images or screenshots analysed.

They only receive an alert indicating that a possible risk situation has been detected and the corresponding category (for example, violence, sexual content, bullying or concealment signals), together with the information necessary to understand the reason for the alert.

Alerts remain associated with the minor's profile exclusively to allow them to be consulted by the authorised father, mother or legal guardian during the established retention period.

These alerts are not used to build profiles of the minor or to make automated decisions.

Are there automated decisions?

No. Guardian Bubble does not make automated decisions that produce legal effects or significantly affect the minor, within the meaning of Article 22 of Regulation (EU) 2016/679.

The Artificial Intelligence only detects possible risk indicators and generates an alert addressed to the responsible adult. The assessment of the situation and any subsequent action always remain the responsibility of the father, mother or legal guardian.

9. WHO DO WE SHARE YOUR DATA WITH?

Guardian Bubble only discloses personal data to third parties where this is necessary to provide the contracted service, to comply with a legal obligation or where the user has expressly authorised it.

Under no circumstances do we sell personal data, disclose information for advertising purposes or allow third parties to use our users' information to build commercial profiles.

Where it is necessary to engage technology providers for the provision of the service, they act as data processors in accordance with Article 28 of Regulation (EU) 2016/679, following our instructions exclusively and applying the security measures required by data protection legislation.

9.1. Data processors

Guardian Bubble uses different specialised technology providers to deliver certain features of the service. All of them have been selected after verifying that they offer sufficient guarantees to protect personal data and are bound by the corresponding data processing agreements.

ProviderPurpose of the processingMain location
Amazon Web Services (AWS)Cloud infrastructure, hosting of the platform, secure storage and operation of the services.eu-south-1 (Milan, Italy)
Google Vertex AITemporary analysis by means of Artificial Intelligence to detect possible risk situations (Android only).europe-west4 (Netherlands)
Google Firebase / FirestoreDatabase, user authentication, synchronisation between devices, technical storage and delivery of push notifications.Eur3 (European Union multi-region)
RevenueCatManagement and validation of subscriptions contracted through Apple App Store and Google Play.Provider's own infrastructure
VideoSDKProvision of the audio communication feature associated with the SOS system.Provider's own infrastructure
Firebase CrashlyticsDetection of technical errors and improvement of the stability of the application. Not used to build profiles or analyse user behaviour.Google infrastructure
Apple App Store and Google PlayDistribution of the applications, management of in-app purchases and processing of subscriptions in accordance with the conditions of each platform.Apple's and Google's own infrastructure
Twilio SendGridDelivery of transactional emails (account verification, service notices).United States (with Standard Contractual Clauses)
Google Maps PlatformDisplay of maps and geocoding services in the responsible adult's application.European Union / United States (with Standard Contractual Clauses)
Firebase Remote Config (Google)Remote configuration of the applications' operating parameters.European Union / United States (with Standard Contractual Clauses)

All of these providers process only the data necessary to provide the corresponding service and may not use it for their own purposes incompatible with the instructions of the Data Controller.

9.2. Disclosures made under a legal obligation

Guardian Bubble may disclose personal data to judicial authorities, law enforcement agencies, administrative authorities or other public bodies where there is a legal obligation or a valid request requiring it to do so. In such cases, only the data strictly necessary to respond to the corresponding request will be provided.

9.3. Communications within the family unit

Certain features of Guardian Bubble necessarily involve the communication of information between the devices linked to the same family unit.

In particular, the father, mother or legal guardian may receive:

  • the minor's location where that feature is activated
  • alerts related to arrival at or departure from previously configured zones
  • SOS alerts sent from the minor's device
  • information on the usage time of the device and of certain applications
  • alerts about possible risk situations detected by means of Artificial Intelligence.

The content analysed by means of Artificial Intelligence is not communicated to the responsible adult. Only the existence of a possible risk situation and the corresponding category are transmitted, so that the parent can assess the situation and, where appropriate, take the measures they consider appropriate.

9.4. Corporate changes

In the event of a merger, acquisition, corporate reorganisation or total or partial transfer of Guardian Bubble's business, personal data may be disclosed to the successor entity where this is necessary to guarantee the continuity of the service. In any event, such disclosure will be made in compliance with data protection legislation and users will be informed where legally required.

10. ARE INTERNATIONAL DATA TRANSFERS CARRIED OUT?

Guardian Bubble endeavours to ensure that personal data is processed, as a general rule, within the European Economic Area.

The main technology services used by the platform are configured in regions located in the European Union, including:

  • Amazon Web Services (eu-south-1 – Milan, Italy)
  • Google Vertex AI (europe-west4 – Netherlands)
  • Google Firebase / Firestore (Eur3 – European Union multi-region).

However, some of the providers used by Guardian Bubble are companies with an international presence. In certain cases, this may mean that certain data is subject to an international data transfer within the meaning of Chapter V of Regulation (EU) 2016/679.

Where this occurs, Guardian Bubble will adopt the appropriate safeguards required by the applicable legislation, including:

  • adequacy decisions adopted by the European Commission
  • standard contractual clauses approved by the European Commission
  • binding corporate rules, where applicable
  • any other mechanism recognised by the legislation in force.

In any event, Guardian Bubble will preferably select providers that allow data processing to remain within the European Economic Area or that offer a level of protection equivalent to that required by the GDPR.

10.1. Transfers arising from Apple and Google

The Guardian Bubble and Guardian Bubble Kids applications are distributed through Apple App Store and Google Play. The use of these platforms means that certain processing operations related to the management of the download of the application, in-app purchases or subscriptions may be subject to Apple's and Google's privacy policies and conditions, with these companies acting as independent controllers in respect of the processing they carry out within the framework of their own services.

We recommend consulting Apple's and Google's privacy policies for detailed information on such processing.

11. HOW LONG DO WE KEEP YOUR DATA?

Guardian Bubble keeps personal data only for the time necessary to fulfil the purposes described in this Privacy Policy or for the periods required by the applicable legislation.

Once the purpose that justified the processing no longer exists, the data will be deleted or, where legally required, kept duly blocked for the periods provided for dealing with possible legal liabilities.

The main retention periods are as follows:

Category of dataRetention period
Account data of the father, mother or legal guardianFor as long as the account remains active.
Identification data of the minorFor as long as the minor remains linked to the family unit.
Location historyMaximum of 30 days, after which it is deleted automatically.
Geofences (configured zones)For as long as they remain active or until deleted by the user.
Application configurationFor as long as the account remains active.
Alerts generated by the systemMaximum of 90 days, after which they are deleted automatically; in any event, they are deleted upon deletion of the account.
Data associated with the SOS functionFor the time strictly necessary to manage the incident and provide the service.
Technical information and operating logsFor the time necessary to guarantee the security, stability and correct operation of the platform.
Subscription-related dataFor the duration of the contractual relationship and thereafter for the periods required by tax, commercial or consumer legislation.
Requests to exercise rightsFor the time necessary to evidence compliance with legal obligations regarding data protection.
Minor's profile with no linked deviceMaximum of 180 days from the unpairing of the last device. After that period without a new pairing, the profile and its associated data are deleted automatically.

The above periods may be extended only where a legal obligation so requires or where necessary for the establishment, exercise or defence of legal claims.

11.1. Account deletion

The father, mother or legal guardian may request the deletion of their account at any time from the application itself or using the contact channels indicated in this Privacy Policy.

Once the deletion of the account is confirmed, Guardian Bubble will, as a general rule, proceed to delete the personal data associated with the user, including the information necessary for the operation of the service, except for data that must be kept temporarily under a legal obligation.

Deletion will include, among other elements:

  • the user account
  • associated profiles
  • location history
  • configured geofences
  • alerts
  • information linked to the SOS function
  • objects stored in the technical infrastructure
  • other data associated with the ordinary operation of the service.

Likewise, where the minor's last device is unpaired without deletion of the profile being requested, the minor's data is kept for a maximum of 180 days to allow a new device to be paired. After that period without the responsible adult pairing a new device, the minor's profile and its associated data are deleted automatically, without prejudice to the specific earlier deletion periods for the location history (30 days) and alerts (90 days).

11.2. Deletion in family units with several parents

Guardian Bubble allows the same family unit to be managed by more than one authorised father, mother or legal guardian.

In such cases, the deletion of one adult's account does not necessarily entail the immediate deletion of the entire family unit, provided that another parent or legal guardian with an administrator profile of the family unit continues to use the service.

In that case:

  • the personal data of the user requesting the deletion will be deleted
  • that user will lose access to the application and to the information associated with the family unit
  • the minor's data and the shared configuration may remain linked to the other parent or legal guardian with an administrator profile who continues to use Guardian Bubble.

When no authorised adult remains linked to the family unit, Guardian Bubble will proceed to delete the family unit and the data associated with the minor, without prejudice to data that must be kept for the time necessary to comply with legal obligations or to deal with possible claims.

Additional adults invited by the administrator (family members) do not assume the administration of the family unit and do not determine its continuity. Such users may at any time request the deletion of their own personal data through the contact channels indicated in this Policy, and their request will be dealt with within the legally established periods.

11.3. Deletion of content analysed by means of Artificial Intelligence

The screenshots and content used to carry out the automated analysis by means of Artificial Intelligence do not form part of the account history.

Such content:

  • is used exclusively to carry out the requested analysis
  • does not remain stored once the process is completed
  • is not incorporated into Guardian Bubble's database
  • is not used to train Artificial Intelligence models
  • is not reused to improve third-party services.

Once the result of the analysis has been generated, the content used during that process is deleted.

11.4. Retention under a legal obligation

In certain cases, Guardian Bubble may keep certain data for an additional period where this is necessary to:

  • comply with a legal obligation
  • respond to requests from competent authorities
  • prevent fraudulent conduct
  • exercise or defend rights in administrative or judicial proceedings.

During that period, the data will remain duly blocked and may only be processed for the purposes indicated above.

12. WHAT ARE YOUR RIGHTS?

Regulation (EU) 2016/679 grants users a series of rights in relation to the processing of their personal data. Guardian Bubble guarantees the exercise of these rights in a simple, free and transparent manner.

At any time, the father, mother or legal guardian may contact the Data Controller or the Data Protection Officer to exercise any of the rights described below.

Where the request relates to the minor's personal data, the exercise of the rights will correspond to the father, mother or legal guardian who holds the legal representation of the minor, without prejudice to the rights that may correspond to the minor themselves under the applicable legislation and taking into account their age and degree of maturity.

12.1. Right of access

You have the right to obtain confirmation as to whether Guardian Bubble is processing personal data concerning you and, if so, to access that information.

In particular, you may find out:

  • what personal data we process
  • for what purpose
  • the origin of the data where it was not provided directly by you
  • the recipients or categories of recipients
  • the envisaged retention period
  • the existence of automated decisions, where applicable.

12.2. Right to rectification

You may request the modification of personal data that is inaccurate, incomplete or out of date. Where technically possible, certain data may be updated directly from the application.

12.3. Right to erasure

You have the right to request the deletion of your personal data where any of the circumstances provided for in Article 17 GDPR apply. Among other cases:

  • where the data is no longer necessary for the purpose for which it was collected
  • where you withdraw your consent, in cases where consent is the legal basis for the processing
  • where the processing is unlawful
  • where there is a legal obligation to delete the data.

Deletion of the account will, as a general rule, entail the deletion of the associated data as provided for in section 11 of this Privacy Policy.

12.4. Right to restriction of processing

You may request that Guardian Bubble temporarily restrict the processing of your personal data where:

  • you contest the accuracy of the data
  • you consider that the processing is unlawful but prefer restriction to deletion
  • you need the data for the establishment, exercise or defence of legal claims
  • you have exercised the right to object while it is being verified whether our legitimate interests prevail.

During that period, the data may only be processed in the cases provided for by the legislation.

12.5. Right to object

Where the processing is based on the legitimate interest of the Controller, you may object to it on grounds relating to your particular situation. In that case, we will stop processing the data unless there are compelling legitimate grounds that prevail over your interests, rights and freedoms, or unless it is necessary for the establishment, exercise or defence of legal claims.

12.6. Right to data portability

Where the processing is based on consent or on the performance of a contract and is carried out by automated means, you may request the delivery of your personal data in a structured, commonly used and machine-readable format, as well as request, where technically possible, its direct transmission to another controller.

12.7. Right not to be subject to automated decisions

Guardian Bubble does not make automated decisions that produce legal effects or significantly affect the minor, within the meaning of Article 22 of Regulation (EU) 2016/679. The Artificial Intelligence features only generate alerts addressed to the father, mother or legal guardian. The assessment of those alerts and any subsequent action is the exclusive responsibility of the responsible adult.

12.8. How can you exercise your rights?

You may exercise any of the rights described above by sending a request to:

Parental Control Tech OÜ — Email address: privacy@guardianbubble.com

or directly to the Data Protection Officer: dpd@consultingnormativo.es

The request must clearly indicate the right you wish to exercise and may be accompanied, where necessary, by documentation allowing the identity of the applicant to be verified.

Guardian Bubble will respond within a maximum period of one month, unless the legislation allows that period to be extended due to the particular complexity of the request.

12.9. Right to lodge a complaint

If you consider that the processing of your personal data does not comply with the legislation in force, you may lodge a complaint with the competent supervisory authority. This is without prejudice to any other administrative or judicial remedy to which you may be entitled under the applicable legislation.

13. HOW DO WE PROTECT YOUR DATA?

Information security is one of the fundamental principles on which Guardian Bubble has been designed. The Data Controller therefore applies appropriate technical and organisational measures to guarantee a level of security appropriate to the risk, in accordance with Article 32 of Regulation (EU) 2016/679.

Among others, Guardian Bubble applies the following measures:

  • encryption of communications using secure protocols
  • user authentication
  • privilege-based access control
  • logical segregation between the different family units
  • monitoring of the technology infrastructure
  • backups and recovery procedures
  • logging and management of security incidents
  • data protection by design and by default
  • minimisation of personal data
  • periodic review of the security measures implemented.

In relation to the Artificial Intelligence features, Guardian Bubble incorporates additional safeguards, including:

  • processing in the europe-west4 region (Netherlands)
  • the technology provider's Zero Data Retention configuration
  • deletion of the analysed content once the process is completed
  • no use of the content to train Artificial Intelligence models
  • absence of automated decisions with legal effects on the minor.

Although no security measure can guarantee absolute protection, Guardian Bubble periodically reviews its systems in order to maintain a level of protection appropriate to technological developments and existing risks.

14. CHANGES TO THIS PRIVACY POLICY

Guardian Bubble may amend this Privacy Policy where necessary to adapt it to regulatory, technical, organisational or functional changes affecting the processing of personal data.

Where the changes are significant, users will be informed through the application itself, the website or other appropriate channels before they come into force.

The date of the last update will always appear at the beginning of this document.

15. CONTACT

If you have any questions about this Privacy Policy or about the processing of your personal data, you can contact us through the following channels:

Data Controller

Parental Control Tech OÜ — Email address: admin@guardianbubble.com — Website: https://www.guardianbubble.com

Data Protection Officer

Consulting Normativo, S.L. — Email address: dpd@consultingnormativo.es

Exercise of rights

Requests relating to the exercise of rights may be addressed either to the Data Controller or to the Data Protection Officer.

16. OUR COMMITMENT TO THE PROTECTION OF MINORS

The protection of minors is the essential purpose of Guardian Bubble.

All the features of the application have been designed seeking to maintain a balance between the minor's safety, respect for their privacy and the responsible exercise of parental authority or guardianship by the father, mother or legal guardian.

Guardian Bubble applies the principles of data protection by design and by default, data minimisation, purpose limitation and proactive accountability, with the aim of guaranteeing that personal information is processed in a transparent, proportionate manner that respects the rights of minors.

Our commitment is to continue reviewing and improving these measures as technology, the applicable legislation and the needs of the families who use our services evolve.

Read this policy in Spanish: Español