Privacy Policy

Version 2.4 · 2026-09-07

1. Controller

Avelia Health, Anton Anders, Wittenberger Str. 91b, 04849 Bad Düben, Germany. Contact: privacy@avelia-health.com.

2. What We Collect

2.1 Website

  • Waitlist & contact forms: Name, email address, phone number, and any information you voluntarily provide (e.g. profession, practice name, organisation name and type, country, registration number). Stored in Listmonk, self-hosted in Germany. Phone numbers are collected for verification purposes only and are not used for marketing.
  • Avelia Fund & partner applications: If you apply through the midwife fastlane or partner application forms, we additionally collect professional details (practice name, profession, registration number) or organisational details (organisation name, type, expected monthly code volume, description). This data is used solely to assess eligibility and is stored in Listmonk.
  • Avelia Fund code requests by email: While our partner network is being established, you may email fund@avelia-health.com to request a free Avelia Fund code. We receive whatever your email carries — your address, your message, and any name attached to it. We do not ask for, and do not want, details of your circumstances. This correspondence is held only in that inbox: it is not stored in Listmonk and is never added to any mailing list.
  • Region cookie: A single functional cookie (jurisdiction) to display the correct legal information for your country. No consent required under GDPR Art. 6(1)(f) as it serves a legitimate interest.
  • Analytics (with consent): If you accept analytics in our cookie banner, we collect anonymous usage statistics via Matomo, self-hosted in Europe. Matomo operates in cookie-less mode — no tracking cookies are set, no personal data is collected, no cross-site tracking occurs. You can withdraw consent at any time by clearing your browser’s localStorage.
  • Server logs: Our web server records IP addresses, request paths, timestamps, and user agents for security and operational purposes. Logs are retained for 30 days and processed under legitimate interest (GDPR Art. 6(1)(f)). IP addresses are anonymised before any analytics processing.

2.2 Mobile App

  • On-device data: Journal entries, tracking data, checklists, and personal notes are stored locally on your device. In the Free tier, this data never leaves your device.
  • Cloud sync (Personal & Together tiers): If you enable cloud sync, your data is end-to-end encrypted on your device before transmission. We receive and store only ciphertext. We are technically unable to read, analyse, or access your content. The encryption keys never leave your device.
  • Partner linking: When you link with a partner, a shared encryption key is exchanged directly between your devices. We facilitate the connection but cannot read shared content.
  • Account data: Email address and hashed password for authentication. Stored in our backend database, hosted in Germany.

3. Legal Basis

ProcessingLegal basis
Account creation & service deliveryContract performance (Art. 6(1)(b))
Region cookieLegitimate interest (Art. 6(1)(f))
AnalyticsConsent (Art. 6(1)(a))
Server logsLegitimate interest (Art. 6(1)(f))
Newsletter / waitlistConsent (Art. 6(1)(a)), double opt-in
Partner / fund application formsConsent (Art. 6(1)(a))
Direct Avelia Fund code requestsPre-contractual steps at your request (Art. 6(1)(b))

4. Data Sharing

We do not sell, trade, or share your personal data with third parties. We do not use any third-party analytics, advertising, or tracking services. All infrastructure is self-hosted in Germany.

Sub-processors: Our server infrastructure is hosted by netcup GmbH and Hetzner Online GmbH, located in Germany. No data is transferred outside the European Economic Area.

5. Data Retention

  • Account data: Retained until you delete your account.
  • Encrypted sync data: Deleted immediately and permanently when you delete your account.
  • Server logs: Anonymised or deleted after 30 days.
  • Newsletter subscribers: Until you unsubscribe.
  • Form submissions (interest, partner, fund applications): Name, email, phone number, and professional/organisational details are retained until the inquiry is resolved or you request deletion.
  • Avelia Fund code requests by email: Your message and your email address are deleted once the code has been sent, and in any case no later than 30 days after your request — whether or not a code was issued. They are never added to our newsletter, our waitlist, or any other list.
  • Expired accounts (Avelia Fund / code-based): After licence expiry, a grace period of 2–4 weeks applies during which sync data remains available. After the grace period, all encrypted sync data is permanently deleted from our servers. Local data on your device is unaffected.

6. Your Rights

Under the GDPR, you have the right to:

  • Access your personal data (Art. 15)
  • Rectification of inaccurate data (Art. 16)
  • Erasure (“right to be forgotten”) (Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20) — export is available in the app
  • Object to processing based on legitimate interest (Art. 21)
  • Withdraw consent at any time without affecting prior processing (Art. 7(3))
  • Lodge a complaint with a supervisory authority

To exercise these rights, contact privacy@avelia-health.com.

7. Security

We employ end-to-end encryption (AES-256-GCM with X25519 key exchange), zero-knowledge architecture, TLS 1.3 for data in transit, and encrypted storage at rest. Our infrastructure is regularly audited. We follow the principle of data minimisation — we only process what is strictly necessary.

8. Children’s Data

Avelia is operated by adults (parents and prospective parents). Children do not create accounts or interact with the service directly. However, parents may enter data about their children — such as names, birth dates, developmental milestones, feeding and sleep logs, and health notes — as a core feature of the app.

This data is protected by the same end-to-end encryption as all other content. We cannot read or access it. It is stored exclusively on your device (Free tier) or as encrypted ciphertext on our servers (paid tiers). When you delete your account, all data about your children is permanently erased.

Children under 16 may not create their own Avelia account. If you believe a child has independently created an account, please contact us and we will delete it immediately.

9. Changes

We may update this policy to reflect changes in our practices or legal requirements. Material changes will be communicated via email or in-app notification. The version number and date at the top of this page indicate the current revision.