EEA / UK Privacy Addendum
Effective Date: April 26, 2026 Last Updated: July 21, 2026
This Addendum supplements the ConKarma Privacy Policy for individuals in the European Economic Area ("EEA"), the United Kingdom, and Switzerland, in line with the General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR, and the Swiss FADP. Capitalised terms not defined here have the meaning given in the main Policy.
1. Controller
XTZ Group, Inc., 2261 Market Street #4524, San Francisco, CA 94114, USA, is the controller for personal data processed via the ConKarma Service.
2. EU / UK Representatives (Art. 27)
Until we appoint a representative under GDPR Art. 27 / UK GDPR Art. 27, you may direct enquiries to legal@conkarma.app. We will appoint and publish a representative prior to opening the Service to the EEA / UK on a sustained basis.
3. Data Protection Officer
We have not appointed a Data Protection Officer. Our processing does not meet the mandatory thresholds in GDPR Art. 37(1) (we are not a public authority, our core activities do not require regular and systematic monitoring on a large scale, and we do not process special categories on a large scale). For privacy enquiries, contact legal@conkarma.app.
4. Categories Processed and Legal Bases (Art. 13)
| Category | Examples | Legal basis |
|---|---|---|
| Account data | email, password hash, display name, birthday | Contract (Art. 6(1)(b)) |
| Cell / family relationships | role, related-account links | Contract |
| User-generated content | journals, missions, messages, images | Contract |
| Adult-feature content | intimacy / fantasy / kink entries | Consent (Art. 6(1)(a)) — opt-in via age-gate confirmation; treated as Art. 9(2)(a) special-category consent in jurisdictions where applicable |
| Health & Fitness data (opt-in) | steps, distance, active minutes, sleep hours, mindful minutes — read from HealthKit / Google Fit / Health Connect, only the categories you grant | Explicit consent (Art. 9(2)(a)) — health data is a "special category" under Art. 9(1); we never process it without your explicit per-category opt-in via the OS-level system permission sheet |
| Communications with us | support tickets | Legitimate interests (Art. 6(1)(f)) — operating support |
| Purchase data (transaction ID, status) | from Apple / Google | Contract |
| Device data, IP, app usage events | from your device | Legitimate interests — security, abuse prevention, debugging; in some jurisdictions cookie / ePrivacy consent applies for non-strictly-necessary analytics |
| Country / region (GeoIP) | resolved from your IP address by our GeoIP sub-processor freeipapi.com (based in Germany) on each request that needs it | Legitimate interests (Art. 6(1)(f)) — security signal for unknown-location login alerts and US-state / regional child-safety gating. Only your IP address is sent to the provider; the resulting country is not persisted beyond the session record and is cached briefly. Because the provider processes within the EEA (Germany), no restricted third-country transfer arises for this lookup. |
We balance legitimate interests against your fundamental rights and document the assessment for each use. You may object at any time to processing under Art. 6(1)(f).
5. Special Categories and Adult Features (Art. 9)
Adult-feature content is treated as a "special category" by analogy to data concerning sex life or sexual orientation (Art. 9(1)). It is processed only on the basis of your explicit opt-in (Art. 9(2)(a)). You may withdraw consent at any time in Settings → Adult; withdrawing consent removes the data and disables the feature. Adult content is never indexed for advertising.
Health and fitness data read from Apple HealthKit, Google Fit, or Health Connect is also a "special category" under Art. 9(1) ("data concerning health"). We process it only on the basis of your explicit consent (Art. 9(2)(a)), captured through the platform-native permission sheet at the moment you tap "Connect health data" inside ConKarma — and only for the categories you tick on that sheet (steps, distance, active minutes, sleep, mindfulness; you can grant any subset). Processing is the minimum necessary for the feature: the daily total is read while the app is in the foreground, the threshold check happens on your device, and only a boolean "threshold crossed today" reaches our servers attached to the relevant mission/duty/experience. Raw health values are not transmitted, persisted, or shared with any third party for any purpose, including advertising — Apple HealthKit's terms of service forbid that, and we honour the rule across both platforms. You can withdraw consent at any time from your device's system Settings (iOS: Settings → Privacy & Security → Health → ConKarma; Android: Settings → Apps → ConKarma → Permissions / Health Connect); withdrawing consent stops the auto-complete flow for that category immediately and we will not push a re-prompt without an explicit user action. The DPIA referenced in §5 has been extended to cover health-data processing (DPIA addendum dated May 2026).
6. International Transfers (Chapter V)
Personal data is processed in the United States. We rely on:
- Standard Contractual Clauses (EU SCCs 2021/914 modules 1 and 2) with our infrastructure providers (Google LLC / Google Ireland Ltd. for Firebase + AdMob; Supabase, Inc. for managed Postgres + object storage, with AWS as Supabase's own downstream infrastructure sub-processor; the standard SMTP relay service used for transactional email).
- EU-U.S. Data Privacy Framework certifications where the recipient is certified (Google LLC is DPF-certified; we transmit DPF transfers under the framework where applicable).
- UK Addendum to the EU SCCs (UK International Data Transfer Addendum) for UK transfers.
Transfer impact assessments are documented and refreshed annually.
7. DPIA — Adult Features
The adult-feature flow has been the subject of an internal Data Protection Impact Assessment under Art. 35 because it processes data analogous to special categories on a non-trivial scale. The DPIA records:
- Purpose limitation: adult content is rendered only inside the adult section, never indexed for advertising or recommendations outside it.
- Data minimisation: content fields are user-authored; we do not collect biometric or device-sensor data in this flow. Precise geolocation is collected only during emergency check-ins when you (or a verified parent on a child's behalf) have turned on Emergency location sharing AND toggled "Share my location with this alert" on the specific check-in. Lawful basis: GDPR Art 6(1)(a) consent. Retention for EEA / UK users: 7 days (Art 5(1)(c) data minimisation); coordinates are deleted after that horizon, while the "safe" / "need help" record itself remains without location. Revocation deletes any retained coordinates within minutes.
- Storage: stored alongside other user content with row-level access checks; encrypted at rest.
- Retention: until you delete the entry or your account.
- Risk mitigations: age-gate at signup and again at adult-section entry; Family-Link / parental-controls block at the platform layer; per-Cell visibility (no cross-Cell sharing); biometric lock available for the adult section.
A summary is available on request to legal@conkarma.app.
8. Your Rights (Art. 15-22)
Subject to local exemptions, you have the right to:
- Access (Art. 15) — Settings → Export my data
- Rectification (Art. 16) — edit in-app or contact support
- Erasure (Art. 17) — Settings → Delete account
- Restriction (Art. 18) — contact us
- Portability (Art. 20) — Export my data returns a machine-readable JSON archive
- Objection (Art. 21) — contact us; we will stop unless we demonstrate compelling legitimate grounds
- Withdraw consent (Art. 7(3)) — without affecting prior lawful processing
You also have the right to lodge a complaint with your supervisory authority. A list is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en. UK residents may complain to the Information Commissioner's Office (https://ico.org.uk).
9. Automated Decision-Making (Art. 22)
We do not make solely-automated decisions that produce legal or similarly significant effects on you.
10. Retention
See Privacy Policy §8. EEA/UK-specific log retention follows the same schedule (request logs 90 days; account data while active plus 30 days for recovery; financial / billing records 7 years).
11. Adult-zone (Ember) — Art. 9 + Art. 5(1)(e)
For EEA / UK users, adult-zone content is processed under Art. 9(2)(a) explicit consent (opt-in via the age-gate confirmation; consent is granular and revocable per Art. 7). Storage is governed by the Art. 5(1)(e) storage-limitation principle:
- Default 3-year retention. Configurable in Settings → Ember privacy from 90 days to 10 years; the user controls the duration. Hard-deleted on window close.
- Per-device enable. Adult-zone access is OFF by default on every non-primary device; you opt in per device. The audit log of changes is retained alongside the user record for the same period as the account.
- Backup-exclusion toggle (Settings → Ember privacy) lets you opt the Ember subset out of iCloud / Drive backups.
- GDPR-export inclusion toggle lets you opt adult-zone rows into your portability export (default OFF — exports stay sharing-safe).
- Withdrawing consent. If you withdraw your adult-zone consent (off-toggle in Settings → Ember privacy), we hard-delete every adult-zone row attributable to you within 30 days; the relevant rows are also excluded from any pending portability export.
- No automated processing without consent (ADR-120). No automated content model processes Ember content without your explicit Art. 9(2)(a) consent; AI features and child-safety moderation of Ember content occur solely under that consent. Children's data is handled under purpose-bound minimisation per the COPPA Data Retention Policy.
- Adult-zone usage analytics (separate opt-in). If you turn on the separate adult-analytics consent (default OFF, distinct from the age-gate confirmation), anonymised, surface-level Ember usage metadata is processed via Google Analytics 4 under Art. 9(2)(a) explicit consent — because usage of adult/intimacy features can, even pseudonymously, imply data concerning sex life or sexual orientation. Safeguards: a pseudonymous GA4 client identifier only (no ConKarma user ID, name, contact, or device identifier), no user-generated content or free text, and feature-key granularity as the ceiling (which feature was used, never which specific act, scene, or content). Google Signals, ads-personalisation, and Google data-sharing are OFF for this stream; it is never used for advertising. You may withdraw this consent at any time in Settings → Ember privacy, independently of your adult-zone access. The Art. 35 DPIA (§7) has been extended to cover this processing.
12. Changes
Material changes to this Addendum are communicated via in-app notice and updated Last Updated date.