Privacy Policy
Last updated: 15.06.2026
We may translate this document into other languages for convenience. In case of any difference or conflict, the English version prevails.
PazAlone is a personal safety app. To work, it must process certain data — but we collect only the minimum necessary.
This Policy explains how we handle your data, especially your location data, when you use PazAlone.
1. Who is responsible for your data?
Data controller (under EU GDPR): PROMUR s.r.o., a company registered in the Slovak Republic, operating under the brand PazAlone Lab.
Registered office: Senný trh 3116/7, 945 01 Komárno, Slovakia.
Company ID: 55917542. VAT ID: SK2122126886.
Contact for privacy and data-protection matters: office@pazalone.com
If you have questions about this Policy, your personal data, or want to exercise your rights, contact us at the address above.
We respond within 30 days.
2. What data we collect
2.1. Account data
We collect account details (display name, email, optional phone number, locale, time zone), your trusted contacts' information, and your app settings (intervals, gentle mode, panic code, panic-code hint).
2.2. Location data (GPS) — strictly event-based
PazAlone DOES NOT track your location in the background during normal daily use.
Location is collected only when one of these specific events occurs:
- a) You manually start a WatchMate session — your last-known location may be pinged briefly so it can be shared if the timer expires.
- b) You trigger a manual emergency alert (red slider) — your last-known location is included in the email sent to your trusted contacts.
2.3. How location data is used
When an emergency alert is triggered, your last-known coordinates are included in the email sent to your trusted contacts, with a Google Maps link.
Location data may be inaccurate or outdated, depending on GPS conditions, device state, and operating-system permissions.
If you cancel an alert (stand-down) or end a WatchMate session safely, no further location is collected.
We do not store location history, a route log, or a movement profile.
PazAlone uses only your last-known location, and only in an emergency.
2.4. Technical data
We process limited technical information required to run the App safely and reliably: device identifier (anti-abuse, recognising the same install across sessions), platform (Android/iOS), app version, IP address, user agent, and basic crash logs.
We do not associate this with your identity beyond what is necessary to operate the service or to respond to a support request.
3. What we never do
PazAlone does not collect, monitor, store, or use:
- Continuous or background location, route history, or movement profile.
- Health records, medical files, or diagnostic data.
- Your phone's contact list, SMS, messaging content, photos, microphone, or camera.
- Payment card details — payments are handled by Apple, Google, or Stripe.
- Behavioural advertising data, web-browsing history, or marketing profiles.
- We do not use ad networks, third-party trackers, or analytics that profile users.
The PazAlone websites (pazalone.com and pazalonelabs.com) use no cookies, no analytics, and no tracking.
4. How we use your information
We use information only to operate PazAlone and to deliver the safety features you have configured.
Notifications and alerts
To send check-in, missed-checkin, emergency-alert, WatchMate, and stand-down emails (and on Pro, SMS) to the trusted contacts you have explicitly configured.
We never sell your data to advertisers or third parties.
Service operation and security
To run the safety timers on our servers, store your settings, and synchronise your account across devices.
To prevent trial abuse, protect against fraud, and respond to security incidents.
Support and legal compliance
To respond to your support requests when you contact us.
To meet legal obligations, including accounting (Slovak law requires retention of billing records for 10 years) and lawful authority requests.
When you add a trusted contact, we send them a short message on your behalf to let them know that you have chosen them as a safety contact.
From it they learn that we will only contact them in an emergency, and how to tell us if they would rather not take part.
We use their contact details for this purpose only.
You manage your trusted contacts yourself; we do not add or remove contacts on your behalf.
If a contact tells us they no longer wish to take part, we will let you know so that you can update your list.
5. Legal bases for processing
We rely on the following legal bases under EU GDPR:
Performance of a contract (Art. 6(1)(b))
Operating the App and its core safety features that you choose to use, managing your subscription.
Legal obligation (Art. 6(1)(c))
Meeting accounting, tax, and lawful authority obligations.
Legitimate interests (Art. 6(1)(f))
Preventing trial abuse, protecting against fraud, and basic technical and security logging — only where these interests are not overridden by your rights and freedoms.
We do not rely on consent for any required processing.
You can opt out of all optional processing through Settings or by contacting office@pazalone.com.
6. Sharing your data
Your data is shared only with the providers strictly required to operate PazAlone.
Each is bound to data-protection terms compliant with GDPR.
Application hosting: Railway (EU and US regions).
Email delivery: Resend (US).
SMS verification and Pro SMS alerts: Twilio (US).
Encrypted backups: Backblaze B2 (EU, Frankfurt).
Subscription processing: Apple, Google, Stripe.
Map preview in alert emails: Google Maps.
When a notification is sent, your name, the type of event, and (where relevant) your last-known location are transmitted to the trusted contacts YOU have explicitly added.
We do not sell, rent, or trade your personal data to anyone, for any purpose.
Where data is transferred outside the European Economic Area, we rely on the EU Standard Contractual Clauses approved by the European Commission.
7. Storage and international transfers
Account data, settings, and audit logs are stored on our servers in Railway (EU/US regions).
Encrypted database backups are stored in Backblaze B2 (Frankfurt, EU).
Some sub-processors are based in the United States.
For those transfers we use the EU Standard Contractual Clauses and additional safeguards where required.
8. How long we keep your data
We keep personal data only as long as necessary for the purposes of this Policy or as required by law.
Active accounts: as long as your account is active.
Soft-deleted accounts: 30 days, then permanently deleted (you can recover during that window).
Suspended accounts (after subscription expiry): kept until you reactivate or delete; not time-limited.
Audit log of system events: 90 days.
Encrypted backups: 30 days.
Billing records: 10 years (Slovak accounting law).
Trusted contact details remain as long as you keep them in the App; you can remove or edit them at any time.
9. Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of your data (right to be forgotten).
- Request restriction of, or object to, certain processing.
- Receive your data in a portable format.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a supervisory authority — in Slovakia: the Office for Personal Data Protection (Úrad na ochranu osobných údajov SR, dataprotection.gov.sk); or in your country of residence.
From inside the App you can edit or remove trusted contacts at any time, change your panic code, and delete your account from Settings.
To exercise your legal rights, contact us at office@pazalone.com.
10. Security
We apply technical and organisational measures appropriate to the risk: HTTPS/TLS encryption in transit, AES-256 encryption for backups, restricted access to production systems, monitoring for suspicious activity.
No method of electronic transmission or storage is 100% secure.
We work continuously to protect your data but cannot guarantee absolute security.
You are also responsible for protecting your device — using a screen lock, keeping your OS updated, controlling who has physical access — and for keeping your panic code reasonably private.
11. Children and young users
PazAlone is not intended for users under 13 years of age.
We strongly recommend that users be at least 16 years old, in line with the GDPR age of digital consent in many EU member states.
If you are a parent or guardian and believe your child under 13 has provided us with personal data, contact us at office@pazalone.com and we will remove it promptly.
PazAlone does not track detailed user behaviour or build profiles of any user, regardless of age.
12. Changes to this Policy
We may update this Policy from time to time.
The current version is always available at pazalone.com/privacy.
When we make material changes, we will update the "Last updated" date and may provide a notice inside the App or by email.
Continued use of the App after changes take effect means you accept the updated Policy.
If you do not agree, please stop using the App and delete your account.
13. Contact
If you have any questions about this Privacy Policy or your data, contact us at:
Email: office@pazalone.com
Website: pazalone.com