Personal Data Processing Policy
This Personal Data Processing Policy (hereinafter the Policy) has been drawn up in accordance with the Law of Ukraine “On Protection of Personal Data” No. 2297-VI of 1 June 2010 (hereinafter the Law) and establishes the procedure for the processing of personal data carried out in the course of providing the service of personal name selection for a child by means of the babybe.app website, and it further sets out the composition of such data, the purpose of and legal grounds for their processing, the list of persons to whom they are transferred, the rights of personal data subjects and the procedure for exercising those rights.
1. General provisions
1.1. This Policy is a public document, is in force for an indefinite term, is made freely available on the babybe.app website and applies to all relations connected with the processing of the personal data of persons who use that website and order the service of personal name selection for a child.
1.2. The owner of the personal data (hereinafter the Owner), being the person whose particulars are set out in Section 2 of this Policy, is the person who, within the meaning of Article 2 of the Law, determines the purpose of the processing of personal data and establishes the composition of such data and the procedure for their processing. In the terminology of European legislation, the Owner acts as the controller.
1.3. The personal data subject (hereinafter the Subject) is the natural person whose personal data are processed in accordance with this Policy, namely the person who uses the Service and who orders and pays for the service. The customer of the service is referred to in this Policy as the personal data subject, and all rights provided for by Article 8 of the Law extend to that person.
1.4. The processing of personal data is carried out by the Owner in compliance with the Constitution of Ukraine, the Law, the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108) and the Additional Protocol thereto (ETS No. 181), ratified by the Law of Ukraine No. 2438-VI of 6 July 2010, and with the other legislative acts of Ukraine in the field of personal data protection.
1.5. Commencement of use of the Service, namely proceeding to the sequence of questions and entering information into the fields of the form, means that the Subject has read the terms of this Policy, understands their content and gives consent to the processing of the Subject’s personal data on the terms established by it, including the terms of Section 8 concerning cross-border transfer.
1.6. Should the Subject disagree with any term of this Policy, the Subject has the right not to commence use of the Service and, with regard to information already entered, to exercise the right to have those data destroyed by applying to the Owner under the procedure established by Section 12 of this Policy.
2. The Owner of the personal data
2.1. The owner of the personal data is Individual entrepreneur Kovalchuk Vadym Volodymyrovych, taxpayer registration number 3637709974.
2.2. Registered address and address for correspondence: 15 Shevchenka St., Malyn, Zhytomyr region, 11601, Ukraine. The actual address coincides with the registered one.
2.3. Email address for enquiries concerning the processing of personal data: hello@babybe.app. Telephone number: +380 73 390 00 00.
2.4. The Owner independently determines the purpose of the processing of personal data, establishes the composition of such data, the procedure for their processing and the list of persons to whom such data are transferred, and bears responsibility for compliance with the requirements of the Law.
2.5. The Owner does not process personal data that present a particular risk to the rights and freedoms of personal data subjects, and accordingly no separate structural unit and no responsible person organising the work connected with the protection of personal data during their processing is established or designated. The personal data protection functions provided for by Article 24 of the Law are performed by the Owner in person.
3. Definitions
3.1. The terms used in this Policy have the meanings defined by Article 2 of the Law, namely:
- 1) personal data: information or a set of information about a natural person who is identified or can be specifically identified;
- 2) processing of personal data: any action or set of actions performed in whole or in part in an information (automated) system and (or) in card files of personal data, which are connected with the collection, registration, accumulation, storage, adaptation, alteration, renewal, use and dissemination (distribution, realisation, transfer), depersonalisation and destruction of information about a natural person;
- 3) owner of personal data: a natural or legal person who determines the purpose of the processing of personal data and establishes the composition of such data and the procedures for their processing, unless otherwise provided by law;
- 4) processor of personal data: a natural or legal person to whom the owner of personal data or the law has granted the right to process those data on behalf of the owner;
- 5) third party: any person other than the personal data subject, the owner or the processor of personal data and the Ukrainian Parliament Commissioner for Human Rights, to whom personal data are transferred by the owner or the processor;
- 6) consent of the personal data subject: the voluntary expression of the will of a natural person to permit the processing of that person’s personal data in accordance with the stated purpose of their processing;
- 7) destruction of personal data: actions as a result of which it becomes impossible to restore the content of personal data in an information (automated) system and (or) as a result of which the physical media of personal data are destroyed.
3.2. In addition, the following terms are used in this Policy:
- 1) the Service: the babybe.app website together with the software by means of which the Owner provides the service of personal name selection for a child;
- 2) the Order: the order for the service placed by the Subject by means of the Service, payment for which is made through the payment service;
- 3) the Result: the list of proposed names generated for the Subject together with the analysis of each of them, access to which is granted by link and communicated to the email address stated by the Subject;
- 4) cookie file: a small text record which the Service places in the memory of the Subject’s browser and which is transmitted to the Service upon subsequent requests from the same browser.
4. Composition of the personal data processed
4.1. Personal data are obtained by the Owner exclusively from the Subject, namely from the information which the Subject voluntarily enters into the fields of the form of the Service, and are also generated automatically as a result of the use of the Service. Personal data are not collected from public registers or from third parties. From advertising services the Owner receives exclusively the identifier of the advertising click through which the Subject arrived at the Service, and information on the effectiveness of advertisements in a pseudonymous form.
4.2. The information entered voluntarily by the Subject comprises wishes concerning the name, the surname and the patronymic, preferred and unwanted names, wishes concerning the length and the rarity of the name, a free-form note, and the email address stated when the Order is placed.
4.3. The list of the composition of personal data set out below is not a text written separately for this Policy. It is generated programmatically from the same registry of records on which operates the software mechanism for the destruction of personal data that the Owner applies upon a demand of the Subject under the procedure established by Section 12 of this Policy. The legal consequence of that method of generation is that no divergence is possible between the list set out in the Policy and the data that are in fact stored and in fact destroyed at the request of the Subject: for this list to become inaccurate, the erasure mechanism itself would have to be altered.
4.4. The composition of the personal data processed by the Owner:
- the surname, the language and the gender wish, which is everything you typed after the test
- the analyses of names that were written
- the internal trace of which names came up for you
- the steps you took through the pages
- the attention trace: which parts of the pages you read
- records of breakages that happened in your browser
- your request for the hands-on search: the messenger, the handle, the name you gave us and anything you added
- the names, the mirror of your wishes, and the profile we took to the model
- your answers to the twelve questions and the time spent on each
- the visitor key and the source markers that tied all of the above together
- the request to the model with your profile, and its answer with the names
- your email
4.5. The Owner does not collect and does not require the provision of the particulars of the Subject’s identity documents, the Subject’s date of birth, place of residence (stay) or telephone number. The personal data of the child for whom the name is selected are not collected. The surname and the patronymic are processed exclusively for the purpose of computing the combination of the name with them and are not used to identify the child or to establish the child’s location.
4.6. The Owner does not process personal data that present a particular risk to the rights and freedoms of personal data subjects and that are listed in Article 7 of the Law, in particular information on racial or ethnic origin, political, religious or ideological beliefs, membership of political parties and trade unions, state of health, criminal convictions, and biometric and genetic data.
4.7. The details of the Subject’s payment card are not processed and not stored by the Owner. Such details are entered by the Subject on the side of the WayForPay payment service, which is a separate owner of personal data in that respect, and those details are neither transferred to nor known by the Owner.
5. Purpose of the processing of personal data
5.1. Personal data are processed by the Owner for the following purposes:
- 1) provision of the service of personal name selection for a child, namely the generation of the Result in accordance with the wishes entered by the Subject;
- 2) securing the Subject’s access to the Result by link, including after the end of the session of use of the Service and from another device;
- 3) conclusion and performance of the contract for the provision of services, which is concluded by the Subject’s accession to the public offer, including identification of the Order and of the payment made under it;
- 4) sending to the email address stated by the Subject a message containing the link to the Result, as well as service messages concerning the Order and payment for it;
- 5) consideration of the Subject’s enquiries, including enquiries concerning the refund of funds and the exercise of the rights provided for by Article 8 of the Law, and the provision of replies to such enquiries;
- 6) performance of the obligations imposed on the Owner by the legislation on accounting and on taxation, and the provision of replies to the bank or the payment service in the event that a payment transaction is disputed;
- 7) ensuring the technical operability of the Service, the continuity of the Subject’s actions across pages, the accounting of the costs of generating the Result, and the detection of faults.
5.2. Processing of personal data for a purpose incompatible with the purposes specified in clause 5.1 of this Policy is not carried out. Personal data are not sold, are not provided to third parties for their own purposes and are not used for the training of natural language processing models.
5.3. The Owner measures the effectiveness of the Owner’s own advertising. For that purpose the advertising services listed in clause 7.4 of this Policy are provided with a pseudonymous visitor key, the advertising click identifier, the device type and, after payment, the number and the amount of the Order. The email address is transferred exclusively in the form of an irreversible digest computed by the SHA-256 algorithm and is not transferred to such services in an open form. The Subject’s answers to the questions of the Service, the surname, the wishes concerning the name and the Result itself are not transferred to advertising services.
5.4. The Owner does not carry out processing of personal data that results in a decision producing legal consequences for the Subject being taken solely on the basis of automated processing.
6. Legal grounds for the processing of personal data
6.1. The legal grounds for the processing of personal data in accordance with Article 11 of the Law are:
- 1) the consent of the Subject to the processing of the Subject’s personal data, given under the procedure established by clause 1.5 of this Policy, in respect of those processing operations which go beyond what is necessary for the performance of the contract;
- 2) the necessity of performing the contract to which the personal data subject is a party, and of taking steps preceding the conclusion of such a contract at the request of the Subject;
- 3) the necessity of performing an obligation of the Owner provided for by law, in particular obligations in the field of accounting and taxation.
6.2. The consent of the Subject is given voluntarily and is specific, informed and unambiguous, since the purpose of the processing, the composition of the personal data, the list of third parties and the terms of cross-border transfer are defined by this Policy before the Subject enters any information and are available to the Subject on every page of the Service.
6.3. The Subject has the right to withdraw the consent given at any time, including by applying to the Owner at the email address hello@babybe.app under the procedure established by Section 12 of this Policy. Withdrawal of consent has no retroactive effect and does not affect the lawfulness of processing carried out before such withdrawal.
6.4. The provision of the personal data specified in Section 4 of this Policy is a necessary condition for the provision of the service. The consequence of failure to provide such information is that generation of the Result and performance of the contract become impossible, of which the Subject is notified before any information is entered.
7. Transfer of personal data to third parties
7.1. The Owner does not disseminate the Subject’s personal data to an indefinite circle of persons and does not transfer them to third parties, save in the cases provided for by this Section and by law.
7.2. In order to provide the service the Owner engages processors of personal data, namely providers of natural language processing models, a payment service and an email delivery service. Such persons process personal data exclusively on behalf of the Owner, within the limits and on the terms determined by the Owner’s instructions, have no right to use those data for their own purposes and are obliged to ensure their protection.
7.3. The list of persons set out below is not a text written separately for this Policy. It is generated programmatically from the list of services actually connected to the Service at the moment of reading it. A service for which no access key has been configured receives no data whatsoever and does not appear in the list. The legal consequence of that method of generation is that the list corresponds to the actual state of the transfer of personal data rather than to the Owner’s intention regarding such transfer.
7.4. The list of persons to whom personal data are transferred, stating the volume of data transferred to each of them:
- Anthropic, OpenAI, DeepSeek (whichever of them has a key configured): your answers, the surname and the wishes, which together make up the request for names
- WayForPay: the email address, the amount and the order number, without which a payment cannot go through
- Resend: the email address and the text of the message carrying the link to your result
- Cloudflare: everything you enter and everything stored: the Service and its database run on its infrastructure, and it also derives the country from the network address
- Google (Google Analytics, Google Ads): a pseudonymous visitor key, the pages you opened, the step you stopped at, and after payment the order number and amount
- Meta Platforms, TikTok: the advertising click identifier, a hashed fingerprint of your email address, the device type, and after payment the order amount
7.5. The transfer of personal data to processors is carried out in the volume necessary to achieve the purposes defined by Section 5 of this Policy, in accordance with the principle of minimisation: each processor receives only that volume of data without which the corresponding action would be impossible. In particular, the Subject’s answers to the questions are not transferred to the payment service, and the Subject’s email address is not transferred to the providers of natural language processing models.
7.6. Personal data may be transferred to public authorities, local self-government bodies and other persons exclusively in the cases, to the extent and under the procedure expressly provided for by law, in particular on the basis of a duly executed request or of a court judgment that has entered into legal force.
8. Cross-border transfer of personal data
8.1. The processing of personal data by the Owner entails their cross-border transfer within the meaning of Article 29 of the Law, since the providers of natural language processing models (Anthropic, OpenAI, DeepSeek, OpenRouter) and the email delivery service (Resend) are foreign parties to relations connected with personal data, and the computing facilities on which the corresponding processing is carried out are located outside the territory of Ukraine, in particular in the territory of Member States of the European Union and in the territory of the United States of America.
8.2. In accordance with part two of Article 29 of the Law, states which are members of the European Economic Area, and states which have signed the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, are recognised as providing an adequate level of protection of personal data. Transfer of personal data to such states is carried out on general grounds and does not require a separate authorisation.
8.3. Transfer of personal data to states not recognised as providing an adequate level of protection of personal data is carried out on the grounds set out in items 1, 2 and 5 of part three of Article 29 of the Law, namely: where the Subject has given unambiguous consent to such transfer; by reason of the necessity of concluding and performing a transaction made in the interests of the Subject and without which provision of the service would be impossible; and subject to the Owner providing appropriate guarantees of non-interference in the private and family life of the Subject.
8.4. By giving consent to the processing of personal data under the procedure established by clause 1.5 of this Policy, the Subject gives unambiguous consent specifically to the cross-border transfer of the Subject’s personal data to the persons named in Section 7, in the volume stated in that same Section, and for the purposes defined by Section 5. The Subject is notified that the legal regime of personal data protection in the state of the recipient may differ from that established by the legislation of Ukraine, and that the scope of the Subject’s rights in such a state may be secured by other legal remedies.
8.5. The guarantees referred to in clause 8.3 of this Policy are secured by the Owner through the following measures:
- 1) engaging exclusively those recipients which have undertaken to process the data transferred to them solely on the instructions of the party commissioning the processing and not to use those data for their own purposes, including for the training of models;
- 2) acceptance of the terms of data processing agreements containing the standard contractual clauses approved by the European Commission, or terms equivalent to them in substance;
- 3) transfer of data exclusively through secure communication channels with the use of cryptographic protection;
- 4) transfer of the minimum necessary volume of data and non-application of cross-border transfer to the information specified in clause 4.6 of this Policy;
- 5) refusal to engage recipients which do not provide the ability to destroy the data transferred to them at the request of the party commissioning the processing.
8.6. Cross-border transfer of personal data to a state recognised by the Verkhovna Rada of Ukraine as an aggressor state, and to temporarily occupied territories, is not carried out.
9. Cookie files
9.1. The Service uses cookie files of a technical nature, which contain the Subject’s session key, the visitor key, the selected interface language and information about the source of the referral, and which secure the continuity of the Subject’s actions across the pages of the Service.
9.2. The purpose of that file is to ensure that the answers entered on one page, the information entered on another and the payment made are attributed to one and the same Subject. In the absence of such a file the provision of the service is technically impossible, since the Service would have no means of establishing to whom the generated Result belongs and to whom access to it is to be granted.
9.3. In addition to the files specified in clause 9.1 of this Policy, the Service uses cookie files of an analytical and advertising nature, which are placed by third-party services engaged by the Owner as processors and listed in clause 7.4 of this Policy. The purpose of such files is to measure at which step the Subject ceases to use the Service, to establish the source of the referral, and to attribute a payment made to the advertisement through which the Subject arrived. The Owner does not sell such information and does not use it to take decisions concerning the Subject.
9.4. The processing of the cookie files specified in clause 9.1 is necessary for the provision of the service ordered by the Subject and is carried out without separate consent. The processing of the cookie files specified in clause 9.3 is carried out on the basis of the Subject’s consent, which is given in the consent banner on the first visit to the Service. Until consent is given, the corresponding files are not placed, and consent once given may be withdrawn at any time by means of the browser in the manner established by clause 9.5 of this Policy.
9.6. The consent banner specified in clause 9.4 of this Policy is shown to Subjects located in the states of the European Economic Area, the United Kingdom and the Swiss Confederation, and also to Subjects whose location could not be established. For other Subjects the processing specified in clause 9.3 is carried out on the basis of the Owner’s legitimate interest in measuring the effectiveness of the Owner’s own advertising, and the Subject has the right to object to it by way of a request in the manner established by section 11 of this Policy.
9.5. The Subject is able to delete cookie files independently by means of the Subject’s browser or to prohibit their storage. The consequence of such a prohibition is that use of the Service becomes impossible, of which the Subject is notified by this Policy.
10. Term of processing and storage of personal data
10.1. Personal data are processed for the term necessary to achieve the purposes defined by Section 5 of this Policy, namely until they are destroyed upon a demand of the Subject under the procedure established by Section 12.
10.2. No specific storage term for personal data is established by the Owner. The ground for this is that the link to the Result has no expiry date: establishing a storage term would have the consequence of terminating the Subject’s access to the service paid for by the Subject without any expression of the Subject’s will, that is to say, of unilaterally depriving the Subject of what the Subject purchased.
10.3. After the erasure of personal data by the Subject, the information which makes it possible to identify the Subject or to identify the Subject specifically is destroyed without the possibility of restoration. Depersonalised information on the fact, amount, date and time of the payment transaction, and on the duration and cost of generating the Result, is retained for the terms established by the legislation on accounting and on taxation and is used exclusively for the refund of funds, the provision of a reply to the bank or the payment service where a transaction is disputed, and the accounting of costs.
10.4. The information referred to in clause 10.3 of this Policy does not make it possible to identify a natural person and does not constitute personal data within the meaning of Article 2 of the Law, and accordingly the right to have it destroyed does not extend to it. The volume of information that is destroyed is determined by clause 4.4 of this Policy, and the volume of information that is retained in depersonalised form is determined by clause 12.6.
11. Rights of the personal data subject
11.1. In accordance with Article 8 of the Law, the Subject has the following rights:
- 1) to know about the sources of collection and the location of the Subject’s personal data, the purpose of their processing, and the location or place of residence (stay) of the owner or processor of personal data, or to give a corresponding instruction to obtain that information to persons authorised by the Subject, save in the cases established by law;
- 2) to receive information on the conditions for granting access to personal data, in particular information on third parties to whom the Subject’s personal data are transferred;
- 3) to have access to the Subject’s personal data;
- 4) to receive, no later than thirty calendar days from the date of receipt of the request, save in the cases provided for by law, a reply as to whether the Subject’s personal data are being processed, and to receive the content of such personal data;
- 5) to submit a reasoned demand to the Owner objecting to the processing of the Subject’s personal data;
- 6) to submit a reasoned demand for the alteration or destruction of the Subject’s personal data by the Owner and by the processor of personal data, if those data are processed unlawfully or are inaccurate;
- 7) to have the Subject’s personal data protected against unlawful processing and accidental loss, destruction or damage in connection with intentional concealment, failure to provide or untimely provision thereof, and to be protected against the provision of information that is inaccurate or defames the honour, dignity and business reputation of a natural person;
- 8) to lodge complaints regarding the processing of the Subject’s personal data with the Ukrainian Parliament Commissioner for Human Rights or with a court;
- 9) to apply legal remedies in the event of a breach of the legislation on the protection of personal data;
- 10) to make reservations concerning the limitation of the right to process the Subject’s personal data when giving consent;
- 11) to withdraw consent to the processing of personal data;
- 12) to know the mechanism of automatic processing of personal data;
- 13) to be protected against an automated decision that has legal consequences for the Subject.
11.2. Supervision of compliance with the legislation on the protection of personal data, within the powers provided for by Article 23 of the Law, is exercised by the Ukrainian Parliament Commissioner for Human Rights. The Subject has the right to apply to the Commissioner with a complaint regarding the processing of the Subject’s personal data under the procedure established by the Law of Ukraine “On Citizens’ Appeals” and by the acts of the Commissioner.
11.3. A prior application to the Owner is not a mandatory condition for lodging a complaint with the Commissioner or a claim with a court, and the absence of such an application does not deprive the Subject of the right to protection. The exercise by the Subject of any of the rights provided for by this Section is free of charge and does not require any explanation of reasons, save in the cases where the reasoned nature of the demand is expressly required by the Law.
12. Exercise of rights and erasure of personal data
12.1. A request for access to personal data, a demand for their alteration or destruction, an objection to processing, and a withdrawal of consent are submitted to the Owner at the email address hello@babybe.app or at the address for correspondence stated in clause 2.2 of this Policy. No other procedure for exercising the rights provided for by Section 11 of this Policy is established, and no separate form for that purpose is provided in the Service.
12.2. A request for access to personal data must contain the information provided for by part two of Article 16 of the Law, namely the surname, first name and patronymic, the place of residence (place of stay) and the details of the document certifying the identity of the requester, information about the Owner, the list of personal data requested, and the purpose of and (or) the legal grounds for the request. The term for examining the request with a view to granting it does not exceed ten working days from the date of its receipt, and the request itself is granted within thirty calendar days from the date of receipt, unless otherwise provided by law.
12.3. A demand for the destruction of personal data is sent to the email address hello@babybe.app. So that the Owner is able to establish which records belong to the Subject, the demand is sent from the email address which the Subject stated when placing the Order, or states the link to the Result, since it is that link which identifies the corresponding record. Submission of an application on paper, the sending of copies of documents and any explanation of reasons are not required.
12.4. Upon receipt of the demand, the Owner establishes the correspondence between the information stated in it and the records being processed, and destroys the personal data by means of the same software mechanism from which the list set out in clause 4.4 of this Policy is generated. The term for considering the demand and the term for providing a reasoned reply are those established by clause 12.2, namely ten working days for consideration and thirty calendar days for the reply.
12.5. The destruction of personal data is irreversible, and restoration of the destroyed information is impossible. Destruction has the consequence of terminating access to the Result, since the information of which it consists is destroyed together with the rest of the data. A demand for destruction constitutes at the same time a withdrawal of consent to the processing of personal data.
12.6. As a result of destruction, part of the records does not disappear entirely but remains an empty shell from which all content has been removed. The reason is that such records are referred to by other records, in particular by the payment record, which the Owner is obliged to retain in order to carry out settlements, to perform the obligations provided for by the legislation on accounting and on taxation, and to provide a reply to the bank or the payment service in the event that a payment transaction is disputed. An empty shell contains no information about a natural person, does not make it possible to identify one and does not constitute personal data within the meaning of Article 2 of the Law.
12.7. The destruction carried out by the Owner concerns the personal data stored in the Owner’s information system. Information saved in the memory of the Subject’s own browser, namely the session key, the selected territories and the open question, is kept on the Subject’s device, and the Owner has neither access to it nor any means of destroying it. Such information is deleted by the Subject independently by means of the browser, in particular by clearing the local storage (localStorage) and the cookie files for the babybe.app website. Until such clearing is performed, that information remains on the Subject’s device even if the data in the Owner’s information system have already been destroyed.
12.8. Should a breach of the requirements of the legislation on the protection of personal data be detected, the Owner takes measures to eliminate it. If elimination of the breach is impossible, the processing of the personal data concerned is terminated and the data themselves are destroyed.
13. Protection of personal data
13.1. The Owner takes organisational and technical measures aimed at protecting personal data against unlawful processing, including against accidental loss, destruction, damage and unauthorised access, as required by Article 24 of the Law.
13.2. Those measures include, in particular:
- 1) transmission of data between the Subject’s browser and the Service exclusively through a secure communication channel with the use of cryptographic protection;
- 2) restriction of access to the data to the circle of persons for whom such access is necessary for the performance of their duties, and delimitation of the rights of such access;
- 3) minimisation of the composition of the data, namely refusal to collect information without which the provision of the service is possible, in particular the particulars of identity documents, the date of birth and the place of residence;
- 4) refusal to store payment card details on the side of the Owner;
- 5) transfer to processors of only that volume of data without which the corresponding action would be impossible;
- 6) the existence of a dedicated software mechanism for the destruction of personal data, which is applied upon a demand of the Subject and requires no manual operations on the database.
13.3. The Owner does not guarantee absolute security of personal data against the unlawful acts of third parties, but undertakes to take all measures within the Owner’s power to prevent them and, in the event of unauthorised access to the Subject’s personal data, to notify the Subject at the email address stated by the Subject when placing the Order.
14. Data of minors
14.1. The Service is intended for adult natural persons having full civil capacity. The Owner has no intention of collecting the personal data of minors and does not offer them the use of the Service.
14.2. The personal data of the child for whom the name is selected are not collected by the Owner. The Service does not request the child’s name, date of birth, particulars of identity documents, place of residence or information on state of health. The surname and the patronymic are processed exclusively for the purpose defined by clause 4.5 of this Policy.
14.3. Should it come to the Owner’s knowledge that the personal data of a minor have been entered into the Service without the consent of the minor’s parents or other legal representatives, such data are destroyed without delay. A person who becomes aware of such a case may report it to the address hello@babybe.app.
15. Amendments to the Policy
15.1. The Owner has the right to make amendments to this Policy. The version of the Policy in force is made freely available on the babybe.app website, and the date of that version is stated at the end of its text.
15.2. Amendments enter into force on the day the new version of the Policy is placed on the website, unless a different term is specified in that version itself. The version of the Policy in force at the moment when the Subject entered the Subject’s personal data applies to relations that arose before the amendments entered into force.
15.3. Amendments that extend the purpose of the processing of personal data, the composition of such data or the list of persons to whom they are transferred apply to the Subject exclusively where the Subject has given consent after such amendments have entered into force.
15.4. This Policy forms an integral part of the public offer placed on the babybe.app website. In the part not governed by this Policy, the parties are guided by the Law and by the other legislative acts of Ukraine.
15.5. The recognition of an individual provision of this Policy as invalid or inapplicable does not entail the invalidity of its other provisions.
Version of 2 September 2026
