Stand: April 2026
Verantwortlicher im Sinne der Datenschutz-Grundverordnung (DSGVO) ist:
Martin Benedix
Elligersweg 85
22307 Hamburg
E-Mail: info@elternhelp.de
Da es sich um eine Einzelperson ohne umfangreiche oder systematische Verarbeitung besonderer Datenkategorien im gewerblichen Maßstab handelt, ist die Benennung eines Datenschutzbeauftragten gemäß Art. 37 DSGVO nicht erforderlich.
ElternHelp ist eine Familienmanagement-App, die Eltern bei der Organisation des Familienalltags unterstützt. Die App stellt Werkzeuge und Informationen bereit, um Eltern beratend zu begleiten. Sämtliche Entscheidungen – insbesondere in medizinischen, behördlichen und erzieherischen Belangen – liegen ausschließlich bei den Nutzerinnen und Nutzern. Die App ersetzt keine professionelle Beratung.
Wir verarbeiten personenbezogene Daten nur soweit dies zur Bereitstellung der App-Funktionen erforderlich ist. Rechtsgrundlagen sind:
Eine automatisierte Entscheidungsfindung einschließlich Profiling im Sinne von Art. 22 DSGVO findet nicht statt.
ElternHelp verwendet ein anonymes Konto-System ohne E-Mail-Adresse, Passwort oder Verknüpfung mit Apple ID, Google-Konto oder anderen Drittanbietern.
Was bedeutet das für Ihre Daten:
Gespeicherte technische Daten zur Authentifizierung: technische Benutzer-ID (zufällig generiert, kein direkter Personenbezug), Anzeigename (frei wählbar, optional), Zeitstempel des letzten Logins.
Beim Einrichten eines Kontos wird ein Recovery-Code erzeugt (Format: ELTERN-XXXX-XXXX-XXXX-XXXX), der den Kontozugang bei Geräteverlust wiederherstellt. Er ist das einzige Zugangsmittel zum Konto.
Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO. Der Recovery-Code-Hash wird bei Konto-Löschung unwiderruflich entfernt.
Beim Erstellen einer Familie wird gespeichert: frei gewählter Familienname (optional), Bundesland (für Schulkalender-Berechnungen), technisch generierter Einladungscode (für Familienmitglieder-Einladung).
Für jedes angelegte Kind können folgende Daten gespeichert werden:
| Feld | Pflicht | Zweck | Rechtsgrundlage |
|---|---|---|---|
| Vorname | Ja | Identifikation innerhalb der Familie | Art. 6 Abs. 1 lit. b DSGVO |
| Geburtsdatum oder errechneter Termin | Ja | Berechnung altersgerechter Meilensteine | Art. 6 Abs. 1 lit. b DSGVO |
| Spitzname | Nein | Anzeige in der App | Art. 6 Abs. 1 lit. b DSGVO |
| Geschlecht | Nein | Personalisierung von Inhalten | Art. 6 Abs. 1 lit. b DSGVO |
| Farbthema | Nein | Visuelle Unterscheidung bei Mehrkindfamilien | Art. 6 Abs. 1 lit. b DSGVO |
| Schulform, Vorschule, Kita-Start | Nein | Berechnung schulbezogener Meilensteine | Art. 6 Abs. 1 lit. b DSGVO |
| Allergien * | Nein | Sicherheitshinweis innerhalb der Familie; Anzeige im Medikamenten-Tracking | Art. 9 Abs. 2 lit. a DSGVO |
| Blutgruppe * | Nein | Information innerhalb der Familie für medizinische Notfälle | Art. 9 Abs. 2 lit. a DSGVO |
| Körpergewicht und -größe * | Nein | Dokumentation innerhalb der Familie | Art. 9 Abs. 2 lit. a DSGVO |
| Chronische Erkrankungen * | Nein | Information innerhalb der Familie | Art. 9 Abs. 2 lit. a DSGVO |
* Gesundheitsdaten nach Art. 9 DSGVO: Die mit * markierten Felder werden nur gespeichert, wenn Sie vorab die Einwilligung zur Verarbeitung von Gesundheitsdaten erteilt haben. Diese Einwilligung können Sie jederzeit widerrufen (Einstellungen → „Einwilligung Gesundheitsdaten widerrufen"). Alle entsprechenden Daten werden dann unwiderruflich gelöscht.
Hinweis zu Kindesdaten: ElternHelp richtet sich ausschließlich an Eltern und Erziehungsberechtigte. Kinder legen selbst keine Konten an und nutzen die App nicht direkt. Kindesdaten werden ausschließlich innerhalb der jeweiligen Familie sichtbar und nicht mit Dritten geteilt.
Rechtsgrundlage für nicht gesundheitsbezogene Kinddaten: Art. 6 Abs. 1 lit. b DSGVO (Vertragserfüllung) in Verbindung mit dem elterlichen Sorgerecht (§§ 1626 ff. BGB).
ElternHelp ermöglicht die freiwillige Erfassung von Gesundheitsdaten im Kindprofil und im Medikamenten-Tracking. Alle nachfolgend genannten Daten werden nur verarbeitet, wenn Sie vorab Ihre ausdrückliche Einwilligung erteilt haben.
Wichtiger Hinweis: ElternHelp ist kein Medizinprodukt. Die App ersetzt keine ärztliche Beratung, Diagnose oder Therapie. Die Entscheidung über Medikamentengaben liegt ausschließlich bei den Erziehungsberechtigten, ggf. in Abstimmung mit medizinischem Fachpersonal. Die App leitet keine Dosierungsempfehlungen, Tageshöchstmengen oder Mindestabstände aus Herstellerangaben oder medizinischen Quellen ab. Sie zeigt ausschließlich von Ihnen selbst eingetragene Daten zurück.
Verarbeitete Gesundheitsdaten (Art. 9 DSGVO): Allergien, Blutgruppe, Körpergewicht und -größe, chronische Erkrankungen des Kindes (sofern eingetragen), Medikamentenname und Wirkstoff, Dosierungsmenge und -einheit, Zeitpunkt der Verabreichung, verabreichende Person (Familienmitglied), Krankheitsfall-Bezeichnung und -verlauf (optional).
Rechtsgrundlage: Art. 9 Abs. 2 lit. a DSGVO – Ihre ausdrückliche Einwilligung, die Sie beim erstmaligen Zugriff auf Gesundheitsfunktionen erteilen.
Speicherdauer: Gesundheitsdaten werden bis zum Widerruf der Einwilligung oder bis zur Konto-Löschung gespeichert – je nachdem, was zuerst eintritt (Art. 13 Abs. 2 lit. a DSGVO).
Diese Einwilligung können Sie jederzeit widerrufen. Widerruf in einem Schritt: Einstellungen → „Einwilligung Gesundheitsdaten widerrufen". Mit dem Widerruf werden alle betroffenen Gesundheitsdaten sowohl lokal auf Ihrem Gerät als auch auf unserem Server unwiderruflich gelöscht.
Ende-zu-Ende-Verschlüsselung: Medikamentennamen, Wirkstoffe, Dosierungseinträge sowie Arztangaben (Name, Hinweise, Datum) werden Ende-zu-Ende-verschlüsselt gespeichert. Ein Datenverlust tritt nur dann ein, wenn alle Geräte aller Familienmitglieder nicht mehr zugänglich sind und der Recovery-Code nicht mehr vorliegt. Einzelne Zugangsverluste lassen sich über den Familien-Einladungscode beheben. Siehe § 10.2 für Details.
Einwilligungs-Nachweis (Art. 7 Abs. 1 DSGVO): Jede erteilte oder widerrufene Einwilligung (Gesundheitsdaten, Push-Benachrichtigungen) wird mit Zeitstempel, Einwilligungstyp und Versionskennung serverseitig protokolliert. Diese Dokumentation dient ausschließlich dem gesetzlich vorgeschriebenen Nachweis der Einwilligung. Die Protokolldaten sind über Row Level Security (RLS) ausschließlich Ihrem Nutzer-Datensatz zugeordnet und werden bei Konto-Löschung automatisch gelöscht (CASCADE).
Diese Funktionen verarbeiten ausschließlich Daten, die Sie selbst eingeben:
Das Schulalltag-Feature ermöglicht die Verwaltung schulbezogener Informationen für Kinder im Schulalter (Stundenplan, Hausaufgaben, Klassenarbeiten/Prüfungen, Klassenfahrten/Schulveranstaltungen, Schulkontakte – jeweils freiwillig).
Hinweis zu Lehrernamen und Schulkontakten (Drittdaten): Wenn Sie Namen oder Kontaktdaten von Lehrpersonen oder sonstigen Schulkontakten eingeben, verarbeiten Sie personenbezogene Daten Dritter. Bitte stellen Sie sicher, dass die betreffenden Personen damit einverstanden sind, oder beschränken Sie die Eingabe auf funktional notwendige Informationen.
Ende-zu-Ende-Verschlüsselung: Alle Schulalltag-Inhalte – Stundenplan, Hausaufgaben, Klassenarbeiten, Klassenfahrten sowie Schulkontakte (Namen, Telefon, E-Mail von Lehrpersonen) – werden Ende-zu-Ende-verschlüsselt gespeichert (AES-GCM-256). Der Betreiber hat keinen Zugriff auf diese Inhalte.
Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO (Vertragserfüllung).
Das Wir-Feature ermöglicht den Austausch zwischen verbundenen Elternteilen. Verarbeitete Daten: Wünsche und Botschaften, Dankbarkeitsnotizen, kleine Gesten, Gesprächsthemen (jeweils Freitext, freiwillig) sowie Emoji-Reaktionen. Diese Daten sind ausschließlich für die verbundenen Personen sichtbar. Es erfolgt keine Analyse, Auswertung oder Weitergabe an Dritte.
Stimmungsdaten (Stimmungsbarometer): Das Wir-Feature enthält ein tägliches Stimmungs-Check-in mit 5 Stufen (Schwierig bis Großartig). Diese Daten sind freiwillig, werden ausschließlich dem verbundenen Partner angezeigt und werden in der aktuellen Form nicht als Gesundheitsdaten nach Art. 9 DSGVO eingestuft, da keine systematische Auswertung oder Verknüpfung mit Gesundheitsprofilen stattfindet.
Hinweis für künftige Funktionen: Sollte eine Auswertung von Stimmungsverläufen über Zeit eingeführt werden, wird eine separate ausdrückliche Einwilligung nach Art. 9 Abs. 2 lit. a DSGVO eingeholt, bevor diese Funktion aktiviert wird.
Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO (Vertragserfüllung).
Diese Funktionen verwenden Ihren GPS-Standort, um nahegelegene Einrichtungen anzuzeigen. Der Standort wird nicht gespeichert und nicht übertragen; die Verarbeitung findet ausschließlich lokal auf Ihrem Gerät statt und nur, wenn Sie die Funktion aktiv aufrufen. Rechtsgrundlage: Art. 6 Abs. 1 lit. a DSGVO (Einwilligung via Betriebssystem-Dialog).
Von Ihnen eingetragene Kontaktdaten Dritter (z. B. Kinderarzt, Hebamme) werden ausschließlich innerhalb Ihrer Familie gespeichert und nicht an Dritte weitergegeben. Bitte stellen Sie sicher, dass die betreffenden Personen der Speicherung zugestimmt haben.
Wenn Sie Push-Benachrichtigungen aktivieren, wird Ihr APNs Device Token (Apple Push Notification Service) auf unserem Server gespeichert. Der Device Token ist ein technischer Identifier Ihres Geräts und wird ausschließlich zur Übermittlung von Benachrichtigungen verwendet. Sie können Push-Benachrichtigungen jederzeit in den Geräte-Einstellungen deaktivieren. Rechtsgrundlage: Art. 6 Abs. 1 lit. a DSGVO (Einwilligung).
Alle Daten werden auf einem selbstbetriebenen Server in Deutschland gespeichert:
Folgende Datenfelder werden Ende-zu-Ende-verschlüsselt gespeichert (AES-GCM-256, CryptoKit): Anzeigenamen der Familienmitglieder, Familienname, Kinddaten (Name, Spitzname, Geburtsdatum, Geschlecht, Blutgruppe, Gewicht, Größe, Allergien, chronische Erkrankungen), Aufgabentitel und -beschreibungen, Inventargegenstände, Medikamentennamen/Wirkstoffe/Dosierungen/Arztangaben, Krankheitsfall-Beschreibungen, Geburtstagsdaten, Aktivitätsnamen und -orte, Tagebucheinträge, Schulalltag-Inhalte, Meilenstein-Inhalte und Notizen sowie Notfallkontakte.
Nicht E2E-verschlüsselt (durch RLS geschützt): technische Metadaten (UUIDs, Zeitstempel) und nicht-sensitive Klassifizierungen (Bundesland, Aufgabenstatus, Meilenstein-Kategorie).
Der Verschlüsselungsschlüssel wird mittels HKDF (HMAC-basierte Schlüsselableitung) aus Ihrem Familien-Einladungscode abgeleitet. Der Schlüssel verlässt Ihr Gerät ausschließlich in verschlüsselter Form und wird nicht im Klartext auf dem Server gespeichert. Ohne den Einladungscode sind die oben genannten Daten für niemanden – auch nicht für den Betreiber – lesbar oder wiederherstellbar.
Hinweis zum Datenverlust-Risiko: Ein dauerhafter Datenverlust tritt nur dann ein, wenn sämtliche Familienmitglieder den Zugang zu allen ihren Geräten verlieren und gleichzeitig kein gültiger Recovery-Code mehr vorhanden ist. In allen anderen Szenarien bleibt der Datenzugang erhalten: Verliert ein einzelnes Familienmitglied den Zugang, kann ein anderes Familienmitglied einen neuen Einladungscode erstellen. Da alle Daten in der Cloud gespeichert sind, gehen dabei keine Inhalte verloren. Bewahren Sie Ihren Recovery-Code sicher auf (z. B. in einem Passwort-Manager).
Zusätzlich zur Cloud werden alle Daten lokal auf Ihrem Gerät gespeichert (iOS: SwiftData / Android: Room Database), um die App auch ohne Internetverbindung nutzbar zu machen. Die lokale Datenbank ist durch die iOS-Datenschutzklassen (Data Protection) geschützt.
Die App bietet optional eine App-Sperre per Face ID oder Touch ID (iOS LocalAuthentication-Framework). Die biometrischen Rohdaten werden ausschließlich durch das Betriebssystem verarbeitet und verlassen das Gerät nicht. ElternHelp erhält ausschließlich einen booleschen Authentifizierungsstatus und speichert keine biometrischen Daten.
Die App stellt ein optionales Home-Screen-Widget bereit. Dafür werden ausgewählte Zusammenfassungen (z. B. nächste anstehende Medikamentengabe) über iOS App Groups in einem gemeinsamen Datenspeicher abgelegt. Es werden keine vollständigen Krankheitsverläufe oder Gesundheitsprofile geteilt, sondern ausschließlich aggregierte Einzelwerte. Der App-Group-Speicher ist auf Geräteebene durch die iOS-Sandbox geschützt.
Regelmäßige verschlüsselte Backups des Servers erfolgen in EU-Rechenzentren (Backblaze B2, EU-Region).
| Maßnahme | Umsetzung |
|---|---|
| Verschlüsselung in Übertragung | TLS 1.3 zwischen App und Server |
| Verschlüsselung im Ruhezustand | AES-GCM-256 (serverseitig + E2E für Inhalte) |
| Ende-zu-Ende-Verschlüsselung | Alle personenbezogenen Inhalte – Betreiber ohne Zugriff; Schlüssel gerätelokal im Keychain; Recovery über Recovery-Code möglich |
| Passwort-/Zugangssicherheit | Kein Passwort; Recovery-Code nur als Hash gespeichert; Klartext verlässt Gerät nicht |
| Zugangskontrolle | Row Level Security (RLS) in Supabase: jeder Nutzer sieht ausschließlich Daten der eigenen Familie |
| Datensparsamkeit | Kein Tracking, keine Analyse, keine Werbe-Profilbildung |
| Backups | Verschlüsselt, EU-Rechenzentrum, regelmäßiger Turnus |
| Serverstandort | Deutschland (Ionos SE, DSGVO-konform) |
Eine Weitergabe Ihrer Daten an Dritte erfolgt nicht, mit folgenden technischen Ausnahmen:
| Empfänger | Sitz | Zweck | Rechtsgrundlage |
|---|---|---|---|
| Ionos SE | Deutschland (EU) | Server-Hosting | Art. 28 DSGVO (AVV) |
| Backblaze Inc. | EU-Region (Amsterdam) | Verschlüsselte Server-Backups | Art. 28 / Art. 46 DSGVO (SCCs) |
| Apple Inc. | USA (DPF-zertifiziert) | Push-Benachrichtigungen (APNs) | Art. 6 Abs. 1 lit. a DSGVO |
| Apple Inc. | USA (DPF-zertifiziert) | App-Vertrieb & Abo-Abrechnung | Art. 6 Abs. 1 lit. b DSGVO |
| Apple Inc. (CLGeocoder) | USA | Adress-Geocoding für Standortsuche (nur bei aktiver Nutzung) | Art. 6 Abs. 1 lit. b DSGVO |
| Open Food Facts / Open Products Facts | Frankreich (EU) | Barcode-Produktabfrage im Inventar-Scanner (EAN-Nummer, nur bei aktivem Scan) | Art. 6 Abs. 1 lit. b DSGVO |
| Ionos VPS (elternhelp.de – eigener Server) | Deutschland (EU) | Optionale Händlerabfrage bei Eigenmarken-Barcodes; Ergebnis wird anonym in geteilter Produktdatenbank gespeichert | Art. 6 Abs. 1 lit. f DSGVO |
Hinweis zum Barcode-Lookup: Beim Scannen eines Barcodes wird die EAN-Nummer an Open Food Facts und Open Products Facts (Open-Source-Projekte, Sitz Frankreich/EU) übertragen. Die EAN selbst erlaubt keine Rückschlüsse auf Ihre Person. Sie können den Scan-Lookup vermeiden, indem Sie Inventarartikel manuell eingeben.
Hinweis zur Community-Produktdatenbank (Eigenmarken): Wenn Sie bei einem unbekannten Barcode optional einen Händler auswählen (dm, Rossmann oder Müller), wird die EAN-Nummer und Ihre Händlerwahl an unseren Server (Ionos VPS, Deutschland) übertragen. Das Ergebnis (Produktname, Marke, Kategorie) wird ohne Nutzer-ID, ohne Familien-ID und ohne sonstiges personenbezogenes Merkmal anonym in einer geteilten Datenbank gespeichert und kommt allen Nutzern zugute. Rechtsgrundlage: Art. 6 Abs. 1 lit. f DSGVO. Die Nutzung ist freiwillig.
Es erfolgt keine Weitergabe an Werbenetzwerke, Analysedienste oder andere Dritte. Es findet kein Tracking statt.
Die Übermittlung von Daten an Apple Inc. (Cupertino, CA, USA) erfolgt auf Basis des EU-U.S. Data Privacy Framework (DPF), dem Apple Inc. zertifiziert ist (Angemessenheitsbeschluss der EU-Kommission vom 10.07.2023). Die Übermittlung ist daher gemäß Art. 45 DSGVO zulässig.
Backblaze, Inc. ist ein US-amerikanisches Unternehmen. Die Datenübermittlung erfolgt auf Basis von Standardvertragsklauseln (SCCs) der EU-Kommission gemäß Art. 46 Abs. 2 lit. c DSGVO. Alle an Backblaze B2 übermittelten Backup-Daten sind AES-GCM-256-verschlüsselt. Backblaze hat zu keinem Zeitpunkt Zugriff auf unverschlüsselte Inhalte.
| Datenkategorie | Speicherdauer |
|---|---|
| Authentifizierungsdaten, Recovery-Code-Hash | Bis zur Konto-Löschung |
| Familienprofile, Kinddaten | Bis zur Familien-Löschung |
| Gesundheitsdaten (Medikamente) | Bis zum Widerruf der Einwilligung oder Konto-Löschung |
| Tagebuch, Schulalltag, Aktivitäten, Geburtstage | Bis zur manuellen Löschung oder Konto-Löschung |
| APNs Device Token | Bis zur Deaktivierung von Push-Benachrichtigungen oder Konto-Löschung |
| Community-Produktdaten (EAN, Produktname, Marke) – anonym | Unbegrenzt (kein Personenbezug, kein Löschanspruch gem. Art. 17 DSGVO) |
| Abo-Transaktions-ID | 10 Jahre (steuerrechtliche Aufbewahrungspflicht gem. § 147 AO) |
Sie haben gemäß DSGVO folgende Rechte:
Zur Ausübung Ihrer Rechte wenden Sie sich an: info@elternhelp.de.
Sie haben außerdem das Recht, sich bei der zuständigen Datenschutzaufsichtsbehörde zu beschweren:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Str. 22, 7. OG, 20459 Hamburg
www.datenschutz-hamburg.de
Wir behalten uns vor, diese Datenschutzerklärung bei Änderungen der App oder der Rechtslage anzupassen. Die jeweils aktuelle Version ist in der App und unter elternhelp.de/datenschutz abrufbar. Bei wesentlichen Änderungen werden Nutzerinnen und Nutzer in der App informiert.
Martin Benedix
E-Mail: info@elternhelp.de
Adresse: Elligersweg 85, 22307 Hamburg
Stand: April 2026
Last updated: April 2026
This is a translation for your convenience. The legally binding version is the German original above; in the event of any discrepancy, the German version prevails.
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Martin Benedix
Elligersweg 85
22307 Hamburg, Germany
E-mail: info@elternhelp.de
As this is an individual who does not carry out extensive or systematic processing of special categories of data on a commercial scale, the designation of a data protection officer pursuant to Art. 37 GDPR is not required.
ElternHelp is a family-management app that helps parents organise everyday family life. The app provides tools and information to support parents in an advisory capacity. All decisions – in particular in medical, administrative and educational matters – rest exclusively with the users. The app is not a substitute for professional advice.
We process personal data only insofar as this is necessary to provide the app's functions. The legal bases are:
No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.
ElternHelp uses an anonymous account system without an e-mail address, password or link to an Apple ID, Google account or other third-party providers.
What this means for your data:
Technical data stored for authentication: technical user ID (randomly generated, no direct personal reference), display name (freely chosen, optional), timestamp of the last login.
When an account is set up, a recovery code is generated (format: ELTERN-XXXX-XXXX-XXXX-XXXX) that restores access to the account if the device is lost. It is the only means of accessing the account.
Legal basis: Art. 6(1)(b) GDPR. The recovery-code hash is irrevocably removed when the account is deleted.
When a family is created, the following is stored: freely chosen family name (optional), federal state (for school-calendar calculations), technically generated invitation code (for inviting family members).
The following data may be stored for each child added:
| Field | Mandatory | Purpose | Legal basis |
|---|---|---|---|
| First name | Yes | Identification within the family | Art. 6(1)(b) GDPR |
| Date of birth or due date | Yes | Calculation of age-appropriate milestones | Art. 6(1)(b) GDPR |
| Nickname | No | Display within the app | Art. 6(1)(b) GDPR |
| Gender | No | Personalisation of content | Art. 6(1)(b) GDPR |
| Colour theme | No | Visual distinction in families with several children | Art. 6(1)(b) GDPR |
| School type, pre-school, day-care start | No | Calculation of school-related milestones | Art. 6(1)(b) GDPR |
| Allergies * | No | Safety note within the family; display in medication tracking | Art. 9(2)(a) GDPR |
| Blood type * | No | Information within the family for medical emergencies | Art. 9(2)(a) GDPR |
| Body weight and height * | No | Documentation within the family | Art. 9(2)(a) GDPR |
| Chronic conditions * | No | Information within the family | Art. 9(2)(a) GDPR |
* Health data under Art. 9 GDPR: the fields marked with * are only stored if you have given prior consent to the processing of health data. You can withdraw this consent at any time (Settings → "Withdraw consent for health data"). All corresponding data is then irrevocably deleted.
Note on children's data: ElternHelp is intended exclusively for parents and legal guardians. Children do not create accounts themselves and do not use the app directly. Children's data is visible only within the respective family and is not shared with third parties.
Legal basis for non-health-related children's data: Art. 6(1)(b) GDPR (performance of a contract) in conjunction with parental custody (Sections 1626 et seq. of the German Civil Code, BGB).
ElternHelp enables the voluntary recording of health data in the child profile and in medication tracking. All data listed below is processed only if you have given your explicit prior consent.
Important note: ElternHelp is not a medical device. The app is not a substitute for medical advice, diagnosis or treatment. The decision on administering medication rests exclusively with the legal guardians, where applicable in consultation with medical professionals. The app does not derive any dosage recommendations, maximum daily amounts or minimum intervals from manufacturer information or medical sources. It merely displays back the data you have entered yourself.
Health data processed (Art. 9 GDPR): the child's allergies, blood type, body weight and height, chronic conditions (if entered), medication name and active ingredient, dosage amount and unit, time of administration, administering person (family member), illness-case name and course (optional).
Legal basis: Art. 9(2)(a) GDPR – your explicit consent, given when you first access the health functions.
Retention period: health data is stored until consent is withdrawn or until the account is deleted, whichever occurs first (Art. 13(2)(a) GDPR).
You can withdraw this consent at any time. Withdrawal in one step: Settings → "Withdraw consent for health data". Upon withdrawal, all affected health data is irrevocably deleted both locally on your device and on our server.
End-to-end encryption: medication names, active ingredients, dosage entries and doctor details (name, notes, date) are stored end-to-end encrypted. Data loss occurs only if all devices of all family members become inaccessible and the recovery code is no longer available. Individual loss of access can be resolved via the family invitation code. See Section 10.2 for details.
Proof of consent (Art. 7(1) GDPR): every consent given or withdrawn (health data, push notifications) is logged on the server with a timestamp, consent type and version identifier. This documentation serves solely as the legally required proof of consent. The log data is assigned exclusively to your user record via Row Level Security (RLS) and is automatically deleted when the account is deleted (CASCADE).
These functions process only data that you enter yourself:
The school-life feature enables the management of school-related information for school-age children (timetable, homework, tests/exams, class trips/school events, school contacts – all voluntary).
Note on teacher names and school contacts (third-party data): if you enter names or contact details of teachers or other school contacts, you are processing personal data of third parties. Please ensure that the persons concerned agree to this, or limit your entries to functionally necessary information.
End-to-end encryption: all school-life content – timetable, homework, tests, class trips and school contacts (teachers' names, phone, e-mail) – is stored end-to-end encrypted (AES-GCM-256). The operator has no access to this content.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
The "Us" feature enables exchange between connected parents. Data processed: wishes and messages, gratitude notes, small gestures, conversation topics (each free text, voluntary) and emoji reactions. This data is visible only to the connected persons. There is no analysis, evaluation or disclosure to third parties.
Mood data (mood barometer): the "Us" feature includes a daily mood check-in with 5 levels (Difficult to Great). This data is voluntary, is shown only to the connected partner and, in its current form, is not classified as health data under Art. 9 GDPR, since no systematic evaluation or linkage with health profiles takes place.
Note on future functions: should an evaluation of mood trends over time be introduced, separate explicit consent under Art. 9(2)(a) GDPR will be obtained before that function is activated.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
These functions use your GPS location to display nearby facilities. The location is not stored and not transmitted; processing takes place exclusively locally on your device and only when you actively invoke the function. Legal basis: Art. 6(1)(a) GDPR (consent via the operating-system dialog).
Contact details of third parties entered by you (e.g. paediatrician, midwife) are stored exclusively within your family and are not disclosed to third parties. Please ensure that the persons concerned have consented to being stored.
If you enable push notifications, your APNs device token (Apple Push Notification Service) is stored on our server. The device token is a technical identifier of your device and is used exclusively to deliver notifications. You can disable push notifications at any time in your device settings. Legal basis: Art. 6(1)(a) GDPR (consent).
All data is stored on a self-operated server in Germany:
The following data fields are stored end-to-end encrypted (AES-GCM-256, CryptoKit): family members' display names, family name, children's data (name, nickname, date of birth, gender, blood type, weight, height, allergies, chronic conditions), task titles and descriptions, inventory items, medication names/active ingredients/dosages/doctor details, illness-case descriptions, birthday data, activity names and locations, journal entries, school-life content, milestone content and notes, and emergency contacts.
Not E2E-encrypted (protected by RLS): technical metadata (UUIDs, timestamps) and non-sensitive classifications (federal state, task status, milestone category).
The encryption key is derived from your family invitation code using HKDF (HMAC-based key derivation). The key leaves your device only in encrypted form and is not stored in plain text on the server. Without the invitation code, the data listed above cannot be read or restored by anyone – not even by the operator.
Note on the risk of data loss: permanent data loss occurs only if all family members lose access to all of their devices and, at the same time, no valid recovery code is available. In all other scenarios, access to the data is preserved: if a single family member loses access, another family member can create a new invitation code. Since all data is stored in the cloud, no content is lost. Keep your recovery code in a safe place (e.g. in a password manager).
In addition to the cloud, all data is stored locally on your device (iOS: SwiftData / Android: Room Database) so that the app can be used without an internet connection. The local database is protected by the iOS data-protection classes.
The app optionally offers an app lock via Face ID or Touch ID (iOS LocalAuthentication framework). The raw biometric data is processed exclusively by the operating system and never leaves the device. ElternHelp receives only a boolean authentication status and does not store any biometric data.
The app provides an optional home-screen widget. For this, selected summaries (e.g. the next upcoming medication dose) are stored in a shared data store via iOS App Groups. No full illness histories or health profiles are shared, only aggregated individual values. The App Group store is protected at device level by the iOS sandbox.
Regular encrypted backups of the server are made in EU data centres (Backblaze B2, EU region).
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS 1.3 between app and server |
| Encryption at rest | AES-GCM-256 (server-side + E2E for content) |
| End-to-end encryption | All personal content – operator has no access; key stored locally on device in the Keychain; recovery possible via recovery code |
| Password/access security | No password; recovery code stored only as a hash; plain text never leaves the device |
| Access control | Row Level Security (RLS) in Supabase: each user sees only their own family's data |
| Data minimisation | No tracking, no analytics, no advertising profiling |
| Backups | Encrypted, EU data centre, on a regular schedule |
| Server location | Germany (Ionos SE, GDPR-compliant) |
Your data is not disclosed to third parties, with the following technical exceptions:
| Recipient | Location | Purpose | Legal basis |
|---|---|---|---|
| Ionos SE | Germany (EU) | Server hosting | Art. 28 GDPR (DPA) |
| Backblaze Inc. | EU region (Amsterdam) | Encrypted server backups | Art. 28 / Art. 46 GDPR (SCCs) |
| Apple Inc. | USA (DPF-certified) | Push notifications (APNs) | Art. 6(1)(a) GDPR |
| Apple Inc. | USA (DPF-certified) | App distribution & subscription billing | Art. 6(1)(b) GDPR |
| Apple Inc. (CLGeocoder) | USA | Address geocoding for location search (only when actively used) | Art. 6(1)(b) GDPR |
| Open Food Facts / Open Products Facts | France (EU) | Barcode product lookup in the inventory scanner (EAN number, only during an active scan) | Art. 6(1)(b) GDPR |
| Ionos VPS (elternhelp.de – own server) | Germany (EU) | Optional retailer lookup for private-label barcodes; result stored anonymously in a shared product database | Art. 6(1)(f) GDPR |
Note on the barcode lookup: when a barcode is scanned, the EAN number is transmitted to Open Food Facts and Open Products Facts (open-source projects based in France/EU). The EAN itself does not allow any conclusions to be drawn about your identity. You can avoid the scan lookup by entering inventory items manually.
Note on the community product database (private labels): if, for an unknown barcode, you optionally select a retailer (dm, Rossmann or Müller), the EAN number and your retailer choice are transmitted to our server (Ionos VPS, Germany). The result (product name, brand, category) is stored anonymously in a shared database without any user ID, family ID or other personal identifier and benefits all users. Legal basis: Art. 6(1)(f) GDPR. Use of this function is voluntary.
There is no disclosure to advertising networks, analytics services or other third parties. No tracking takes place.
The transfer of data to Apple Inc. (Cupertino, CA, USA) is based on the EU-U.S. Data Privacy Framework (DPF), to which Apple Inc. is certified (EU Commission adequacy decision of 10 July 2023). The transfer is therefore permissible under Art. 45 GDPR.
Backblaze, Inc. is a US company. The data transfer is based on the EU Commission's Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. All backup data transmitted to Backblaze B2 is AES-GCM-256 encrypted. Backblaze never has access to unencrypted content.
| Data category | Retention period |
|---|---|
| Authentication data, recovery-code hash | Until the account is deleted |
| Family profiles, children's data | Until the family is deleted |
| Health data (medication) | Until consent is withdrawn or the account is deleted |
| Journal, school life, activities, birthdays | Until manually deleted or the account is deleted |
| APNs device token | Until push notifications are disabled or the account is deleted |
| Community product data (EAN, product name, brand) – anonymous | Indefinite (no personal reference; no right to erasure under Art. 17 GDPR) |
| Subscription transaction ID | 10 years (statutory tax retention obligation, Section 147 of the German Fiscal Code, AO) |
Under the GDPR you have the following rights:
To exercise your rights, please contact: info@elternhelp.de.
You also have the right to lodge a complaint with the competent data protection supervisory authority:
The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Str. 22, 7th floor, 20459 Hamburg, Germany
www.datenschutz-hamburg.de
We reserve the right to amend this Privacy Policy in the event of changes to the app or the legal situation. The current version is available in the app and at elternhelp.de/datenschutz. In the event of material changes, users will be informed in the app.
Martin Benedix
E-mail: info@elternhelp.de
Address: Elligersweg 85, 22307 Hamburg, Germany
Last updated: April 2026
Son güncelleme: Nisan 2026
Bu, kolaylık sağlamak amacıyla hazırlanmış bir çeviridir. Yasal olarak bağlayıcı sürüm yukarıdaki Almanca özgün metindir; herhangi bir tutarsızlık durumunda Almanca sürüm geçerlidir.
Avrupa Genel Veri Koruma Tüzüğü (GDPR) anlamında veri sorumlusu:
Martin Benedix
Elligersweg 85
22307 Hamburg, Almanya
E-posta: info@elternhelp.de
Söz konusu olan, özel nitelikli veri kategorilerini ticari ölçekte kapsamlı veya sistematik biçimde işlemeyen bir gerçek kişi olduğundan, GDPR 37. madde uyarınca bir veri koruma görevlisi atanması gerekli değildir.
ElternHelp, ebeveynlerin aile hayatını düzenlemesine yardımcı olan bir aile yönetimi uygulamasıdır. Uygulama, ebeveynlere danışmanlık niteliğinde destek olmak için araçlar ve bilgiler sunar. Tüm kararlar – özellikle tıbbi, resmi ve eğitimle ilgili konularda – yalnızca kullanıcılara aittir. Uygulama, profesyonel danışmanlığın yerini tutmaz.
Kişisel verileri yalnızca uygulamanın işlevlerinin sağlanması için gerekli olduğu ölçüde işleriz. Hukuki dayanaklar şunlardır:
GDPR 22. madde anlamında profil çıkarma dahil otomatik karar verme işlemi yapılmaz.
ElternHelp; e-posta adresi, parola veya Apple ID, Google hesabı ya da başka üçüncü taraf sağlayıcılarla bağlantı olmadan çalışan bir anonim hesap sistemi kullanır.
Bunun verileriniz için anlamı:
Kimlik doğrulama için saklanan teknik veriler: teknik kullanıcı kimliği (rastgele oluşturulur, doğrudan kişisel bağ yoktur), görünen ad (serbestçe seçilir, isteğe bağlı), son oturum açma zaman damgası.
Bir hesap oluşturulduğunda, cihaz kaybı durumunda hesap erişimini geri yükleyen bir kurtarma kodu (biçim: ELTERN-XXXX-XXXX-XXXX-XXXX) oluşturulur. Bu, hesaba erişimin tek yoludur.
Hukuki dayanak: GDPR Madde 6(1)(b). Kurtarma kodu özeti, hesap silindiğinde geri döndürülemez biçimde kaldırılır.
Bir aile oluşturulduğunda şunlar saklanır: serbestçe seçilen aile adı (isteğe bağlı), eyalet (okul takvimi hesaplamaları için), teknik olarak oluşturulan davet kodu (aile üyelerini davet etmek için).
Eklenen her çocuk için aşağıdaki veriler saklanabilir:
| Alan | Zorunlu | Amaç | Hukuki dayanak |
|---|---|---|---|
| Ad | Evet | Aile içinde tanımlama | GDPR Madde 6(1)(b) |
| Doğum tarihi veya tahmini doğum tarihi | Evet | Yaşa uygun kilometre taşlarının hesaplanması | GDPR Madde 6(1)(b) |
| Takma ad | Hayır | Uygulamada görüntüleme | GDPR Madde 6(1)(b) |
| Cinsiyet | Hayır | İçeriğin kişiselleştirilmesi | GDPR Madde 6(1)(b) |
| Renk teması | Hayır | Birden çok çocuklu ailelerde görsel ayrım | GDPR Madde 6(1)(b) |
| Okul türü, anaokulu, kreş başlangıcı | Hayır | Okulla ilgili kilometre taşlarının hesaplanması | GDPR Madde 6(1)(b) |
| Alerjiler * | Hayır | Aile içinde güvenlik notu; ilaç takibinde görüntüleme | GDPR Madde 9(2)(a) |
| Kan grubu * | Hayır | Tıbbi acil durumlar için aile içi bilgi | GDPR Madde 9(2)(a) |
| Vücut ağırlığı ve boy * | Hayır | Aile içinde belgeleme | GDPR Madde 9(2)(a) |
| Kronik hastalıklar * | Hayır | Aile içinde bilgi | GDPR Madde 9(2)(a) |
* GDPR Madde 9 kapsamındaki sağlık verileri: * ile işaretli alanlar yalnızca sağlık verilerinin işlenmesine önceden rıza vermeniz halinde saklanır. Bu rızayı istediğiniz zaman geri alabilirsiniz (Ayarlar → "Sağlık verileri rızasını geri al"). İlgili tüm veriler daha sonra geri döndürülemez biçimde silinir.
Çocuk verilerine ilişkin not: ElternHelp yalnızca ebeveynlere ve yasal vasilere yöneliktir. Çocuklar kendileri hesap oluşturmaz ve uygulamayı doğrudan kullanmaz. Çocuk verileri yalnızca ilgili aile içinde görünür ve üçüncü taraflarla paylaşılmaz.
Sağlıkla ilgili olmayan çocuk verileri için hukuki dayanak: GDPR Madde 6(1)(b) (sözleşmenin ifası), ebeveyn velayeti ile bağlantılı olarak (Alman Medeni Kanunu, BGB, madde 1626 vd.).
ElternHelp, çocuk profilinde ve ilaç takibinde sağlık verilerinin gönüllü olarak kaydedilmesine olanak tanır. Aşağıda belirtilen tüm veriler yalnızca önceden açık rızanızı vermeniz halinde işlenir.
Önemli uyarı: ElternHelp bir tıbbi cihaz değildir. Uygulama, tıbbi tavsiye, teşhis veya tedavinin yerini tutmaz. İlaç verilmesine ilişkin karar yalnızca yasal vasilere aittir, gerektiğinde tıbbi uzmanlara danışılarak. Uygulama, üretici bilgilerinden veya tıbbi kaynaklardan herhangi bir doz önerisi, günlük azami miktar veya asgari aralık türetmez. Yalnızca sizin girdiğiniz verileri size geri gösterir.
İşlenen sağlık verileri (GDPR Madde 9): çocuğun alerjileri, kan grubu, vücut ağırlığı ve boyu, kronik hastalıkları (girilmişse), ilaç adı ve etkin madde, doz miktarı ve birimi, uygulama zamanı, uygulayan kişi (aile üyesi), hastalık durumu adı ve seyri (isteğe bağlı).
Hukuki dayanak: GDPR Madde 9(2)(a) – sağlık işlevlerine ilk eriştiğinizde verdiğiniz açık rıza.
Saklama süresi: sağlık verileri, rıza geri alınana veya hesap silinene kadar (hangisi önce gerçekleşirse) saklanır (GDPR Madde 13(2)(a)).
Bu rızayı istediğiniz zaman geri alabilirsiniz. Tek adımda geri alma: Ayarlar → "Sağlık verileri rızasını geri al". Geri alma ile ilgili tüm sağlık verileri hem cihazınızda yerel olarak hem de sunucumuzda geri döndürülemez biçimde silinir.
Uçtan uca şifreleme: ilaç adları, etkin maddeler, doz kayıtları ve doktor bilgileri (ad, notlar, tarih) uçtan uca şifreli olarak saklanır. Veri kaybı yalnızca tüm aile üyelerinin tüm cihazlarına erişilemez hale gelmesi ve kurtarma kodunun da artık mevcut olmaması durumunda gerçekleşir. Tekil erişim kayıpları aile davet kodu üzerinden giderilebilir. Ayrıntılar için bkz. Bölüm 10.2.
Rıza kanıtı (GDPR Madde 7(1)): verilen veya geri alınan her rıza (sağlık verileri, anlık bildirimler) sunucu tarafında zaman damgası, rıza türü ve sürüm tanımlayıcısı ile kaydedilir. Bu belgeleme yalnızca yasal olarak zorunlu rıza kanıtı amacına hizmet eder. Kayıt verileri, Satır Düzeyi Güvenlik (RLS) aracılığıyla yalnızca kullanıcı kaydınıza atanır ve hesap silindiğinde otomatik olarak silinir (CASCADE).
Bu işlevler yalnızca sizin girdiğiniz verileri işler:
Okul hayatı özelliği, okul çağındaki çocuklar için okulla ilgili bilgilerin yönetilmesine olanak tanır (ders programı, ödevler, sınavlar, sınıf gezileri/okul etkinlikleri, okul kişileri – hepsi isteğe bağlı).
Öğretmen adları ve okul kişilerine ilişkin not (üçüncü taraf verileri): öğretmenlerin veya diğer okul kişilerinin adlarını ya da iletişim bilgilerini girerseniz, üçüncü tarafların kişisel verilerini işlemiş olursunuz. Lütfen ilgili kişilerin buna rıza gösterdiğinden emin olun veya girişlerinizi işlevsel olarak gerekli bilgilerle sınırlayın.
Uçtan uca şifreleme: tüm okul hayatı içerikleri – ders programı, ödevler, sınavlar, sınıf gezileri ve okul kişileri (öğretmenlerin adı, telefon, e-posta) – uçtan uca şifreli olarak saklanır (AES-GCM-256). İşletmecinin bu içeriğe erişimi yoktur.
Hukuki dayanak: GDPR Madde 6(1)(b) (sözleşmenin ifası).
"Biz" özelliği, bağlı ebeveynler arasında paylaşımı mümkün kılar. İşlenen veriler: dilekler ve mesajlar, minnettarlık notları, küçük jestler, konuşma konuları (her biri serbest metin, gönüllü) ve emoji tepkileri. Bu veriler yalnızca bağlı kişiler tarafından görülebilir. Herhangi bir analiz, değerlendirme veya üçüncü taraflara aktarım yapılmaz.
Ruh hali verileri (ruh hali barometresi): "Biz" özelliği, 5 düzeyli (Zor'dan Harika'ya) günlük bir ruh hali kaydını içerir. Bu veriler gönüllüdür, yalnızca bağlı eşe gösterilir ve mevcut haliyle GDPR Madde 9 kapsamında sağlık verisi olarak sınıflandırılmaz; çünkü sistematik bir değerlendirme veya sağlık profilleriyle ilişkilendirme yapılmaz.
Gelecekteki işlevlere ilişkin not: zaman içindeki ruh hali eğilimlerinin değerlendirilmesi getirilirse, bu işlev etkinleştirilmeden önce GDPR Madde 9(2)(a) uyarınca ayrı bir açık rıza alınacaktır.
Hukuki dayanak: GDPR Madde 6(1)(b) (sözleşmenin ifası).
Bu işlevler, yakındaki tesisleri göstermek için GPS konumunuzu kullanır. Konum saklanmaz ve iletilmez; işleme yalnızca cihazınızda yerel olarak ve yalnızca işlevi etkin biçimde çağırdığınızda gerçekleşir. Hukuki dayanak: GDPR Madde 6(1)(a) (işletim sistemi iletişim kutusu üzerinden rıza).
Girdiğiniz üçüncü taraf iletişim bilgileri (ör. çocuk doktoru, ebe) yalnızca ailenizde saklanır ve üçüncü taraflara aktarılmaz. Lütfen ilgili kişilerin saklanmaya rıza gösterdiğinden emin olun.
Anlık bildirimleri etkinleştirirseniz, APNs cihaz belirteciniz (Apple Push Notification Service) sunucumuzda saklanır. Cihaz belirteci, cihazınızın teknik bir tanımlayıcısıdır ve yalnızca bildirimlerin iletilmesi için kullanılır. Anlık bildirimleri istediğiniz zaman cihaz ayarlarınızdan devre dışı bırakabilirsiniz. Hukuki dayanak: GDPR Madde 6(1)(a) (rıza).
Tüm veriler Almanya'da kendi işlettiğimiz bir sunucuda saklanır:
Aşağıdaki veri alanları uçtan uca şifreli olarak saklanır (AES-GCM-256, CryptoKit): aile üyelerinin görünen adları, aile adı, çocuk verileri (ad, takma ad, doğum tarihi, cinsiyet, kan grubu, ağırlık, boy, alerjiler, kronik hastalıklar), görev başlıkları ve açıklamaları, envanter öğeleri, ilaç adları/etkin maddeler/dozlar/doktor bilgileri, hastalık durumu açıklamaları, doğum günü verileri, etkinlik adları ve yerleri, günlük girişleri, okul hayatı içerikleri, kilometre taşı içerikleri ve notları ile acil durum kişileri.
Uçtan uca şifreli olmayan (RLS ile korunan): teknik meta veriler (UUID'ler, zaman damgaları) ve hassas olmayan sınıflandırmalar (eyalet, görev durumu, kilometre taşı kategorisi).
Şifreleme anahtarı, aile davet kodunuzdan HKDF (HMAC tabanlı anahtar türetme) ile türetilir. Anahtar cihazınızdan yalnızca şifreli biçimde çıkar ve sunucuda açık metin olarak saklanmaz. Davet kodu olmadan yukarıda belirtilen veriler hiç kimse tarafından – işletmeci tarafından bile – okunamaz veya geri getirilemez.
Veri kaybı riskine ilişkin not: kalıcı veri kaybı yalnızca tüm aile üyelerinin tüm cihazlarına erişimini kaybetmesi ve aynı anda geçerli bir kurtarma kodunun da bulunmaması durumunda gerçekleşir. Diğer tüm senaryolarda verilere erişim korunur: tek bir aile üyesi erişimini kaybederse, başka bir aile üyesi yeni bir davet kodu oluşturabilir. Tüm veriler bulutta saklandığından hiçbir içerik kaybolmaz. Kurtarma kodunuzu güvenli bir yerde saklayın (ör. bir parola yöneticisinde).
Buluta ek olarak, uygulamanın internet bağlantısı olmadan da kullanılabilmesi için tüm veriler cihazınızda yerel olarak saklanır (iOS: SwiftData / Android: Room Database). Yerel veritabanı, iOS veri koruma sınıflarıyla korunur.
Uygulama, isteğe bağlı olarak Face ID veya Touch ID ile bir uygulama kilidi sunar (iOS LocalAuthentication çerçevesi). Ham biyometrik veriler yalnızca işletim sistemi tarafından işlenir ve cihazdan çıkmaz. ElternHelp yalnızca bir mantıksal (boolean) kimlik doğrulama durumu alır ve hiçbir biyometrik veri saklamaz.
Uygulama, isteğe bağlı bir ana ekran widget'ı sunar. Bunun için seçili özetler (ör. yaklaşan bir sonraki ilaç dozu) iOS App Groups aracılığıyla ortak bir veri deposunda saklanır. Tam hastalık geçmişleri veya sağlık profilleri paylaşılmaz, yalnızca toplu tekil değerler paylaşılır. App Group deposu, cihaz düzeyinde iOS sandbox ile korunur.
Sunucunun düzenli şifreli yedeklemeleri AB veri merkezlerinde yapılır (Backblaze B2, AB bölgesi).
| Önlem | Uygulama |
|---|---|
| Aktarım sırasında şifreleme | Uygulama ile sunucu arasında TLS 1.3 |
| Beklemede şifreleme | AES-GCM-256 (sunucu tarafı + içerik için uçtan uca) |
| Uçtan uca şifreleme | Tüm kişisel içerikler – işletmecinin erişimi yok; anahtar cihazda yerel olarak Keychain'de; kurtarma kodu ile geri getirme mümkün |
| Parola/erişim güvenliği | Parola yok; kurtarma kodu yalnızca özet olarak saklanır; açık metin cihazdan çıkmaz |
| Erişim kontrolü | Supabase'de Satır Düzeyi Güvenlik (RLS): her kullanıcı yalnızca kendi ailesinin verilerini görür |
| Veri en aza indirme | İzleme yok, analiz yok, reklam profili çıkarma yok |
| Yedeklemeler | Şifreli, AB veri merkezi, düzenli aralıklarla |
| Sunucu konumu | Almanya (Ionos SE, GDPR uyumlu) |
Verileriniz, aşağıdaki teknik istisnalar dışında üçüncü taraflara aktarılmaz:
| Alıcı | Konum | Amaç | Hukuki dayanak |
|---|---|---|---|
| Ionos SE | Almanya (AB) | Sunucu barındırma | GDPR Madde 28 (veri işleme sözleşmesi) |
| Backblaze Inc. | AB bölgesi (Amsterdam) | Şifreli sunucu yedeklemeleri | GDPR Madde 28 / Madde 46 (SCC) |
| Apple Inc. | ABD (DPF sertifikalı) | Anlık bildirimler (APNs) | GDPR Madde 6(1)(a) |
| Apple Inc. | ABD (DPF sertifikalı) | Uygulama dağıtımı ve abonelik faturalandırması | GDPR Madde 6(1)(b) |
| Apple Inc. (CLGeocoder) | ABD | Konum araması için adres coğrafi kodlaması (yalnızca etkin kullanımda) | GDPR Madde 6(1)(b) |
| Open Food Facts / Open Products Facts | Fransa (AB) | Envanter tarayıcısında barkod ürün sorgusu (EAN numarası, yalnızca etkin tarama sırasında) | GDPR Madde 6(1)(b) |
| Ionos VPS (elternhelp.de – kendi sunucumuz) | Almanya (AB) | Özel marka barkodları için isteğe bağlı satıcı sorgusu; sonuç paylaşılan ürün veritabanında anonim olarak saklanır | GDPR Madde 6(1)(f) |
Barkod sorgusuna ilişkin not: bir barkod tarandığında, EAN numarası Open Food Facts ve Open Products Facts'e (Fransa/AB merkezli açık kaynak projeleri) iletilir. EAN'in kendisi kimliğiniz hakkında herhangi bir çıkarım yapılmasına izin vermez. Envanter öğelerini elle girerek tarama sorgusundan kaçınabilirsiniz.
Topluluk ürün veritabanına ilişkin not (özel markalar): bilinmeyen bir barkod için isteğe bağlı olarak bir satıcı seçerseniz (dm, Rossmann veya Müller), EAN numarası ve satıcı seçiminiz sunucumuza (Ionos VPS, Almanya) iletilir. Sonuç (ürün adı, marka, kategori), herhangi bir kullanıcı kimliği, aile kimliği veya başka bir kişisel tanımlayıcı olmadan paylaşılan bir veritabanında anonim olarak saklanır ve tüm kullanıcılara fayda sağlar. Hukuki dayanak: GDPR Madde 6(1)(f). Bu işlevin kullanımı gönüllüdür.
Reklam ağlarına, analiz hizmetlerine veya diğer üçüncü taraflara hiçbir aktarım yapılmaz. Hiçbir izleme gerçekleşmez.
Apple Inc.'e (Cupertino, CA, ABD) veri aktarımı, Apple Inc.'in sertifikalı olduğu AB-ABD Veri Gizliliği Çerçevesi (DPF) temelinde gerçekleşir (AB Komisyonu'nun 10 Temmuz 2023 tarihli yeterlilik kararı). Bu nedenle aktarım GDPR Madde 45 uyarınca hukuka uygundur.
Backblaze, Inc. bir ABD şirketidir. Veri aktarımı, AB Komisyonu'nun Standart Sözleşme Maddeleri (SCC) temelinde GDPR Madde 46(2)(c) uyarınca gerçekleşir. Backblaze B2'ye iletilen tüm yedekleme verileri AES-GCM-256 ile şifrelenmiştir. Backblaze'in hiçbir zaman şifrelenmemiş içeriğe erişimi yoktur.
| Veri kategorisi | Saklama süresi |
|---|---|
| Kimlik doğrulama verileri, kurtarma kodu özeti | Hesap silinene kadar |
| Aile profilleri, çocuk verileri | Aile silinene kadar |
| Sağlık verileri (ilaç) | Rıza geri alınana veya hesap silinene kadar |
| Günlük, okul hayatı, etkinlikler, doğum günleri | Elle silinene veya hesap silinene kadar |
| APNs cihaz belirteci | Anlık bildirimler devre dışı bırakılana veya hesap silinene kadar |
| Topluluk ürün verileri (EAN, ürün adı, marka) – anonim | Süresiz (kişisel bağ yok; GDPR Madde 17 uyarınca silme hakkı yok) |
| Abonelik işlem kimliği | 10 yıl (Alman Vergi Kanunu, AO, madde 147 uyarınca yasal saklama yükümlülüğü) |
GDPR uyarınca aşağıdaki haklara sahipsiniz:
Haklarınızı kullanmak için lütfen iletişime geçin: info@elternhelp.de.
Ayrıca yetkili veri koruma denetim makamına şikâyette bulunma hakkına sahipsiniz:
Hamburg Veri Koruma ve Bilgi Edinme Özgürlüğü Sorumlusu
Ludwig-Erhard-Str. 22, 7. kat, 20459 Hamburg, Almanya
www.datenschutz-hamburg.de
Uygulamadaki veya hukuki durumdaki değişiklikler halinde bu Gizlilik Politikasını değiştirme hakkımızı saklı tutarız. Güncel sürüm uygulamada ve elternhelp.de/datenschutz adresinde mevcuttur. Önemli değişikliklerde kullanıcılar uygulama içinde bilgilendirilir.
Martin Benedix
E-posta: info@elternhelp.de
Adres: Elligersweg 85, 22307 Hamburg, Almanya
Son güncelleme: Nisan 2026