Privacy policy
Last updated: 15 June 2026
This document may be translated into other languages for convenience. In the event of any inconsistency or discrepancy, the English version shall prevail.
PazAlone is a personal-safety app. For it to work, we must process certain data — but we collect only the necessary minimum.
This policy explains how we handle your data — especially your location — when you use PazAlone.
1. Who is responsible for your data?
Data controller (under the EU GDPR): PROMUR s.r.o., a company registered in the Slovak Republic, operating under the PazAlone Lab brand name.
Registered office: Senný trh 3116/7, 945 01 Komárno, Slovakia.
Company registration number: 55917542.
VAT number: SK2122126886.
Contact for privacy and data-protection matters: office@pazalone.com
If you have questions about this Policy, your personal data, or want to exercise your rights, contact us at the address above.
We respond within 30 days.
2. What data we collect
2.1. Account data
We collect account details (display name, email, optional phone number, locale, time zone), your trusted contacts' information, and your app settings (intervals, gentle mode, panic code, panic-code hint).
2.2. Location data (GPS) — STRICTLY EVENT-BASED
PazAlone DOES NOT track your location in the background during normal daily use.
Location is collected only when one of these specific events occurs:
- When a WatchMate session is started — your last known location can be requested for a short time so that it can be shared if the timer expires.
- When a manual emergency alert is triggered (red slider) — your last known location is included in the email sent to your trusted contacts.
2.3. How location data is used
When an emergency alert is triggered, your last-known coordinates are included in the email sent to your trusted contacts, with a Google Maps link.
Location data may be inaccurate or outdated, depending on GPS conditions, device state, and operating-system permissions.
If you cancel an alert (stand-down) or end a WatchMate session safely, no further location is collected.
We do not store location history, a route log, or a movement profile.
PazAlone uses only your last-known location, and only in an emergency.
2.4. Technical data
We process limited technical information required to run the App safely and reliably: device identifier (anti-abuse, recognising the same install across sessions), platform (Android/iOS), app version, IP address, user agent, and basic crash logs.
We do not associate this with your identity beyond what is necessary to operate the service or to respond to a support request.
3. What information we do not collect
PazAlone does not collect, monitor, store, or use:
- Continuous background location data, route history or movement profiles.
- Health or medical data.
- Your phone's contacts, SMS messages, message contents, photos, microphone or camera.
- Bank card details — payments are handled by Apple, Google or Stripe.
- Behavioural data for advertising, browsing history or marketing profiles.
- Advertising networks, third-party tracking code or profiling analytics.
Data recorded in the Safety Vault is stored locally on your device only; it is not transferred to our servers and PROMUR s.r.o. has no access to it.
The PazAlone websites (pazalone.com and pazalonelabs.com) use no cookies, no analytics, and no tracking.
4. How we use information
We use information only to operate PazAlone and to deliver the safety features you have configured.
Notifications and alerts
To send check-in, missed-checkin, emergency-alert, WatchMate, and stand-down emails (and on Pro, SMS) to the trusted contacts you have explicitly configured.
We never sell your data to advertisers or third parties.
Service operation and security
To run the safety timers on our servers, store your settings, and synchronise your account across devices.
To prevent trial abuse, protect against fraud, and respond to security incidents.
Support and legal compliance
To respond to your support requests when you contact us.
To meet legal obligations, including accounting (Slovak law requires retention of billing records for 10 years) and lawful authority requests.
When you add a trusted contact, we send them a short message on your behalf to let them know that you have chosen them as a safety contact.
From it they learn that we will only contact them in an emergency, and how to tell us if they would rather not take part.
We use their contact details for this purpose only.
You manage your trusted contacts yourself; we do not add or remove contacts on your behalf.
If a contact tells us they no longer wish to take part, we will let you know so that you can update your list.
5. Legal bases (GDPR)
We rely on the following legal bases under EU GDPR:
Performance of a contract (Art. 6(1)(b))
Operating the App and its core safety features that you choose to use, managing your subscription.
Legal obligation (Art. 6(1)(c))
Meeting accounting, tax, and lawful authority obligations.
Legitimate interests (Art. 6(1)(f))
Preventing trial abuse, protecting against fraud, and basic technical and security logging — only where these interests are not overridden by your rights and freedoms.
We do not rely on consent for any required processing.
You can opt out of all optional processing through Settings or by contacting office@pazalone.com.
6. Who we share data with (sub-processors)
Your data is shared only with the providers strictly required to operate PazAlone.
Each is bound to data-protection terms compliant with GDPR.
- Application hosting: Railway (EU and US regions).
- Email delivery: Resend (US).
- SMS verification and Pro SMS notifications: Twilio (US).
- Encrypted backups: Backblaze B2 (EU, Frankfurt).
- Subscription processing: Apple, Google, Stripe.
- Map preview in notification emails: Google Maps.
When a notification is triggered, your name, the type of event and (where relevant) your last known position are passed on to the trusted contacts you have expressly added.
We do not sell, rent, or trade your personal data to anyone, for any purpose.
Where data is transferred outside the European Economic Area, we rely on the EU Standard Contractual Clauses approved by the European Commission.
7. Where data is stored
Account data, settings, and audit logs are stored on our servers in Railway (EU/US regions).
Encrypted database backups are stored in Backblaze B2 (Frankfurt, EU).
Some sub-processors are based in the United States.
For those transfers we use the EU Standard Contractual Clauses and additional safeguards where required.
8. How long we keep data
We keep personal data only as long as necessary for the purposes of this Policy or as required by law.
- Active accounts: for as long as the account exists.
- Accounts marked for deletion: recoverable for 30 days, after which they are permanently deleted.
Suspended accounts (after subscription expiry): kept until you reactivate or delete; not time-limited.
- Automatic system event logs: 90 days.
- Encrypted backups: 30 days.
- Billing records: 10 years (under Slovak accounting legislation).
Trusted contact details remain as long as you keep them in the App; you can remove or edit them at any time.
9. Your rights and control over your data
Under GDPR you have the right to:
- To request access to the personal data held about you.
- To request the correction of inaccurate or incomplete data.
- To request the erasure of your personal data (“right to be forgotten”).
- To request the restriction of certain processing, or to object to it.
- To receive your personal data in a portable format.
- To withdraw your consent at any time, where the processing is based on consent.
- To lodge a complaint with a supervisory authority — in Slovakia: the Office for Personal Data Protection (Úrad na ochranu osobných údajov SR, dataprotection.gov.sk), or with the competent authority in your country of residence.
From inside the App you can edit or remove trusted contacts at any time, change your panic code, and delete your account from Settings.
To exercise your legal rights, contact us at office@pazalone.com.
10. Security
We apply technical and organisational measures appropriate to the risk: HTTPS/TLS encryption in transit, AES-256 encryption for backups, restricted access to production systems, monitoring for suspicious activity.
No method of electronic transmission or storage is 100% secure.
We work continuously to protect your data but cannot guarantee absolute security.
You are also responsible for protecting your device — using a screen lock, keeping your OS updated, controlling who has physical access — and for keeping your panic code reasonably private.
11. Children and young users
PazAlone is not intended for users under 13 years of age.
We strongly recommend that users be at least 16 years old, in line with the GDPR age of digital consent in many EU member states.
If you are a parent or guardian and believe your child under 13 has provided us with personal data, contact us at office@pazalone.com and we will remove it promptly.
PazAlone does not track detailed user behaviour or build profiles of any user, regardless of age.
12. Changes to this Privacy Policy
We may update this Policy from time to time.
The current version is always available at pazalone.com/privacy.
When we make material changes, we will update the "Last updated" date and may provide a notice inside the App or by email.
Continued use of the App after changes take effect means you accept the updated Policy.
If you do not agree, please stop using the App and delete your account.
13. Contact
If you have any questions about this Privacy Policy or your data, contact us at:
Email: office@pazalone.com
Website: pazalone.com