Heart Rate - Pulse Checker App

Manage and track your blood pressure easily with the our app on your iOS device. 

DOWNLOAD LEARN MORE TERMS OF USE

Heart Rate - Pulse Checker App
Data Protection Policy

Released: 08. 09. 2025

Controller: Hertox Package Kft, József körút 69. fszt. 1., 1085 Budapest, Hungary
Contact: [email protected]

1. Introduction & Scope

1.1. This Privacy Policy explains how we collect, use, disclose, transfer, and protect personal information when you use our iOS application (the “App”). It applies to data collected directly from you, data you authorize us to obtain from third parties, and data automatically collected by your device while using the App

1.2. We may update this Policy from time to time. We will post updates in the App and/or on our website and adjust the effective date above. Your continued use indicates acceptance. If you disagree, please discontinue use of the App.

1.3. Platform focus: This version is tailored to Apple App Store requirements. If the App is distributed on other platforms, their specific notices may apply in addition

2. Key Definitions

2.1. Personal Information means any information relating to an identified or identifiable individual

2.2. Processing means any operation performed on personal information (collection, storage, use, disclosure, deletion, etc.).

2.3. Controller means Hertox Package Kft, which determines purposes and means of processing.

2.4. Processors/Service Providers are vendors processing personal data on our behalf under contract.

2.5. Tracking (ATT) means linking user/device data collected from the App with third‑party data for targeted advertising/measurement, or sharing data with data brokers.

3. Categories of Personal Information We Collect

3.1. Depending on the features you use, we may collect:

  • 3.1.1. Contact Information: name, email address, phone (if provided).
  • 3.1.2. Identifiers: internal user ID, device ID, Apple IDFA (only with ATT opt‑in), IP address.
  • 3.1.3. Account & Profile Data: credentials (hashed), preferences, settings.
  • 3.1.4. Usage Data: App interactions, event logs, crash diagnostics, performance metrics
  • 3.1.5. Location Data: approximate or precise location (with permission).
  • 3.1.6. Device Data: device model, OS version, language, time zone, network.
  • 3.1.7. Purchase Data: in‑app purchase (IAP) history, subscription status, receipt metadata (we do not receive full card details).
  • 3.1.8. Content You Provide: feedback, support messages, files or media you choose to share.
  • 3.1.9. Permissions‑based Data: camera, microphone, photos, contacts, calendar, Bluetooth (requested only if a feature needs it).

3.2. Just‑in‑time disclosure: iOS shows purpose strings when requesting each permission. We present clear purpose explanations and request the minimum necessary access. You can change permissions any time in iOS Settings.

4. Sources of Personal Information

4.1. Directly from you (registration, support, forms, feedback).

4.2. Automatically from your device (logs, diagnostics, usage).

4.3. From third parties with your authorization (e.g., social sign‑ins if offered).

5. Purposes & Legal Bases (GDPR/UK GDPR)

Purpose Examples Legal basis
Provide/operate the App authentication, core features, syncing Contract (Art. 6(1)(b))
Customer support troubleshooting, replying to requests Legitimate interests (Art. 6(1)(f)) and/or Contract
Personalization preferences, saved settings Legitimate interests / Consent
Analytics/diagnostics crash logs, performance Legitimate interests
Payments & subscriptions manage IAP status/receipts Contract / Legal obligation
Security & fraud prevention abuse detection, rate‑limiting Legitimate interests / Legal obligation
Marketing communications transactional vs. (optional) marketing Consent / Legitimate interests
Targeted ads/attribution ad delivery/measurement (if enabled) Consent (ATT opt‑in)

Where we rely on consent, you may withdraw it at any time in the App and/or iOS Settings; this does not affect prior lawful processing.

6. Tracking, Advertising, and ATT (Apple)

6.1. We do not access Apple IDFA or engage in tracking without your explicit ATT consent when iOS prompts you (“Allow App to Track?”).

6.2. If you decline, we do not use IDFA and limit advertising/measurement to non‑tracking methods

6.3. You can change your choice in Settings → Privacy & Security → Tracking.

6.4. We do not link personal information to advertising identifiers without your consent.

6.5. Push notifications: We send push notifications only if you opt in.
Promotional pushes are sent only with your explicit consent and can be disabled in iOS Settings.

7. iOS Permissions We May Request (Examples)

7.1. Location to enable location‑dependent features (e.g., localized experiences).

7.2. Camera/Microphone to capture content or enable in‑App calls (if applicable).

7.3. Photos to upload or save images you select.

7.4. Contacts/Calendar to import contacts or events upon your request.

7.5. Bluetooth to connect supported accessories (if applicable).

7.6. We request access only when required for a feature and explain the purpose at the moment of request.

8. Disclosures of Personal Information

8.1. We share personal information only as follows:

  • 8.1.1. Service Providers (Processors): hosting, analytics, messaging, customer support, crash reporting. They act under contract and only on our instructions.
  • 8.1.2. Analytics & Measurement Partners: to understand App usage and improve functionality. Any tracking use is limited to your ATT consent.
  • 8.1.3. Advertising Partners (if enabled): to deliver ads or measure performance only with ATT consent. We do not sell personal information.
  • 8.1.4. Affiliates/Corporate transactions: in case of reorganization, merger, or asset sale under the same privacy commitments.
  • 8.1.5. Legal/Safety: to comply with law, enforce terms, or protect rights, safety, and property.

8.2. A current list of major processors/SDKs is provided in Appendix B.

9. Data Retention & Deletion

9.1. We retain personal data only as long as necessary for the purposes above or as required by law. Default schedule (unless legal requirements dictate otherwise):

Data category Typical retention
Account/profile data for the life of the account; deleted upon account deletion
Usage/analytics 12–24 months (aggregated/anonymized thereafter)
Support records up to 24 months after resolution
Transaction/IAP metadata per tax/accounting law (often 6–10 years in the EU)
Logs & diagnostics 90–365 days (security logs may be retained longer if necessary)

9.2. In‑App account deletion: You can delete your account directly within the iOS App (Settings → Delete Account). After you initiate deletion, we remove or anonymize personal data within reasonable timeframes, except where retention is required for legal claims, accounting, fraud prevention, or compliance.

10. Your Privacy Rights

  • 10.1. EU/EEA/UK
    • 10.1.1. Right of access; rectification; erasure; restriction; portability; objection (including to direct marketing); right not to be subject to solely automated decisions; and the right to withdraw consent at any time. You may lodge a complaint with your data protection authority.
  • 10.2. United States (state laws)
    • 10.2.1. California (CCPA/CPRA) and similar laws (e.g., Colorado/Connecticut/Virginia/Utah) grant rights to access, correct, delete, portability, and to opt out of targeted advertising, “sale,” and certain profiling. Some states provide an appeals process if we deny a request.
  • 10.3. To exercise rights, contact [email protected]. We will verify your identity and respond within statutory timelines. Authorized agent procedures are available where required.
  • 10.4. App Store privacy label: In addition to these rights, you can review the App’s Privacy Label on the App Store listing to see high‑level data categories, whether they are linked to you, and whether they are used for tracking.

11. International Data Transfers

11.1. If personal data is transferred outside the EU/EEA/UK, we use appropriate safeguards (e.g., adequacy decisions or Standard Contractual Clauses) and supplementary measures where necessary.

12. Security

12.1 We implement administrative, technical, and physical safeguards appropriate to the risks, including encryption in transit, access controls, least‑privilege principles, vulnerability management, and secure development practices. No method is 100% secure. If we learn of a breach that affects your information, we will notify you and regulators as required by law.

13. Children’s Privacy

13.1. The App is not directed to children under 13. We do not knowingly collect personal information from children under 13 (COPPA). If you believe a child has provided information, please contact us; we will promptly delete it. Where GDPR applies, we do not target users below the age of digital consent.

14. External Links

14.1 The App may link to third‑party websites/services. We are not responsible for their privacy or security practices. Review their policies before providing any information.

15. Contact

15.1. Questions or requests? Contact [email protected] or use any in‑App tools provided

Appendix A — App Store Privacy Labels Mapping (Draft)

Map your actual data practices to Apple’s privacy label categories (confirm prior to release).

Apple label category Collected? Linked to user? Used for tracking? Purpose(s)
Contact Info (email, name) Yes Yes No Account, support, communications
Identifiers (User ID, Device ID, IDFA) Yes Yes Only with ATT consent Account, analytics; tracking only with consent
Purchases Yes Yes No IAP/subscription management, receipts
Location Possibly Yes/No (feature‑dependent) No Feature enablement, analytics (approximate)
Usage Data (product interaction) Yes Yes No/Consent‑base Analytics, improvement
Diagnostics (crash data) Yes No No Stability, troubleshooting
Sensitive Info No (by default Not collected unless a feature explicitly requires it with consent

Appendix B — Processors, SDKs, and Key Third Parties

  • Hosting/Backend: [Vendor], processing region, purpose.
  • Analytics: [Vendor], SDK version, data points (events, device info), retention, opt‑out.
  • Crash Reporting: [Vendor], data (stack traces, device state).
  • Messaging/Push: Apple Push Notification service (APNs); [Vendor] for in‑app messaging
  • Attribution/Ads (if enabled): [Vendor]; used only with ATT consent; data shared for measurement.
  • Support/Helpdesk: [Vendor] (ticket metadata, email).

Appendix C — Regional Disclosures (Detailed)

  • EU/EEA/UK: Controller and legal bases (see Section 5). International transfers via SCCs or adequacy. Right to lodge a complaint with your data protection authority.
  • California (CPRA): We do not sell personal information. If we “share” personal information for cross‑context behavioral advertising, you may opt out. Sensitive personal information is used only as permitted by law.
  • Colorado/Connecticut/Virginia/Utah (and similar laws): rights to access, correct, delete, portability, and opt out of targeted advertising, sale, and certain profiling. Appeals instructions provided upon request.

Appendix D — Retention Rationale & Minimization

We apply data minimization and purpose limitation principles. Retention aligns with operational needs and legal obligations (e.g., tax, accounting, fraud prevention). We aggregate or anonymize data where feasible to reduce privacy risk.