App privacy policy

Last updated:

Who is responsible

The controller of the data in the Mosicu app is Less Than Three, S.L.U., Carrer Pere d'Urg, 10, Edifici Mont-Ducal, 5è, AD500 Andorra la Vella (Principality of Andorra), NRT L-716734-S. Privacy contact: hola@mosicu.tech.

We apply Andorra's Llei 29/2021, of 28 October, on personal data protection and, for users in the European Union, the GDPR (Regulation (EU) 2016/679).

What data we process and why

DataWhyLegal basis
Your account email and password (the password is stored hashed, never in plain text)To let you sign inContract
Farms, animals, herds, zones and animal photosTo provide the serviceContract
Positions, activity, temperature, battery and signal sent by the collarsTo show where your animals are, alert you and create reportsContract
Email addresses of people you share a farm withTo give them access and, if enabled, send them the invitationLegitimate interest of the person sharing; the invitee can object
Your phone's notification token and languageTo send you alertsContract
Preferences (weekly summary, read alerts, settings)To make the app work the way you set it upContract

The app does not use your phone's location: the map shows the collars, not where you are. We don't access your contacts. We don't sell data, show ads or track you across apps or websites.

Where it is stored and who processes it

Data is stored in the European Union, in Paris (Supabase, on Amazon Web Services, region eu-west-3). The providers that process it on our behalf are:

  • Supabase: database, user accounts and photos.
  • Cloudflare: receives collar data through api.mosicu.tech and passes it on to the database without storing it.
  • Google Firebase Cloud Messaging and Apple Push Notification service: delivering notifications.
  • Resend: sending invitation emails, when that feature is enabled.
  • Esri: satellite map imagery. It only receives the map area you're viewing and, like any web server, your IP address; no account data.

The base map, built from OpenStreetMap data, is served from our own servers in Paris.

Some of these providers are in the United States. Transfers rely on the legal safeguards in force: the EU–US Data Privacy Framework or standard contractual clauses.

How long we keep it

  • Account data: for as long as you keep your account.
  • Collar position history, readings and alerts: deleted after 2 years.
  • Expired invitations: deleted after 90 days.

You can delete your account in the app under Settings > Delete account. This deletes your data and any farms that are yours alone. If someone else manages a farm with you, the farm becomes theirs.

Anonymised data

To improve activity detection and alerts, when sensor readings are deleted (on account deletion or after 2 years) we keep an anonymised copy: no farm, person, names, photos or zones, and positions converted into relative movements that don't reveal where the animals were. Because it can't be linked back to you, it is no longer personal data.

Security

All connections are encrypted (TLS). Access to data is restricted per farm and per person, each collar has its own key, and your app session is stored in your phone's secure keychain.

Your rights

You can access, correct, erase (also via Settings > Delete account), restrict, object to and ask for portability of your data by emailing hola@mosicu.tech. If we have reasonable doubts about your identity, we may ask you to confirm it.

If you're not satisfied, you can complain to the Andorran Data Protection Agency (APDA), www.apda.ad, or to the data protection authority in your EU country.

Children

The app is not intended for anyone under 16.

Changes

If we change this policy, we'll publish the new version on this page with its update date and, if the change is significant, let you know in the app or by email.

Questions? See our support page or email us. Website privacy is covered in our Privacy policy.