PRIVACY POLICY
Last updated: January 2025
This Privacy Policy explains how FDM Digital GmbH (“we”, “us”, or “our”) handles your personal data when you use the Drink & Milk mobile application.
1. Data Controller
FDM Digital GmbH
Stampfenbachstrasse 115
8006 Zürich, Switzerland
For questions about this Privacy Policy, please contact us through our contact form
2. Data We Collect
Personal Data:
Stored locally on your device (and optionally in your account):
- Physical metrics: age, weight, height
- Breastfeeding information: baby’s age, feeding type
- Drink history and timing data
- Account information (if you create an account): email address, profile settings
Exported data capabilities:
- Full drink history in CSV/JSON format
- Safety timeline reports
- Usage statistics for healthcare provider consultations
Anonymous Analytics Data via Amplitude Analytics:
- App usage patterns and navigation flows
- Feature usage statistics and performance metrics
- Crash reports and error diagnostics
- Device type, operating system version, and app version
- Session duration and frequency (no personal identification)
We do NOT collect:
- Names, email addresses, or contact information
- Location data
- Photos or camera access
- Any personally identifiable information (PII)
3. How We Use Your Data
Local Data (on your device):
- Calculate personalized alcohol clearance times
- Store your drink history and preferences
- Provide safety notifications and reminders
Account Data (if you create an account):
- Synchronize your data across devices
- Backup your drink history and settings
- Enable data export functionality
Anonymous Analytics via Amplitude:
- Improve app performance and user experience
- Identify and fix technical issues and crashes
- Understand feature adoption and usage patterns
- Optimize user interface and navigation flows
5. Data Storage and Security
- Personal data remains primarily on your device with optional cloud backup for account users
- Account data (if created) is securely stored on AWS servers in EU/Switzerland regions
- Anonymous analytics are processed through Amplitude Analytics with privacy safeguards
- All data transmission uses industry-standard encryption (TLS/SSL)
- We implement access controls and regular security audits
- Data export functionality allows you to download your complete data history
6. Third-Party Services
We use the following third-party services:
Amazon Web Services (AWS) for:
- Account storage: Secure cloud backup for optional user accounts (EU/Switzerland regions)
- Data hosting: Infrastructure with GDPR-compliant data processing agreements
Amplitude Analytics for:
- Anonymous usage analytics and behavioral insights
- Crash reporting and performance monitoring
- Product improvement and feature optimization
No personal data is shared with Amplitude – only anonymous, aggregated usage patterns. All services process data according to their privacy policies and our data processing agreements.
7. Your Rights (GDPR)
You have the following rights regarding your personal data:
- Access: View and export your data through the app’s export functionality
- Correction: Edit your profile information and drink history in the app
- Deletion: Delete your account and all associated data, or clear local data
- Portability: Export your complete data history in standard formats (CSV/JSON)
- Objection: Disable analytics collection in app settings
- Withdraw Consent: Delete your account or disable data collection features at any time
To exercise these rights, use the app’s built-in features or contact us through our contact form
8. Data Retention
- Local data: Retained until you delete it or uninstall the app
- Account data: Retained while your account is active; deleted within 30 days of account closure
- Anonymous analytics: Retained for up to 24 months for improvement purposes (Amplitude standard)
- Exported data: Under your control once downloaded
9. International Transfers
- Account data is stored primarily in AWS EU/Switzerland regions to minimize international transfers
- Anonymous analytics are processed by Amplitude (US-based) with GDPR-compliant safeguards including Standard Contractual Clauses
- All international transfers comply with GDPR requirements and adequate protection measures
9. Children’s Privacy
This app is not intended for anyone under 18 years old. We do not knowingly collect data from minors.
10. Changes to This Policy
We may update this Privacy Policy. Changes will be communicated through the app.
11. Contact Us
For privacy questions or to exercise your rights, please contact us through our contact form