Privacy Policy for the Borcook App
This Privacy Policy describes the rules for processing personal data in connection with the use of the Borcook mobile application, the account in the App, local and cloud functions, recipes, Programs, subscriptions, support services, diagnostics and community features.
1. Data controller
The controller of personal data of App Users is BORNIAK – ZUT BORNIAK Dawid Szurlej, Al. Niepodległości 41, 78-449 Borne Sulinowo, Poland, VAT ID/NIP: PL8992343025, REGON: 021138535.
Contact for data protection matters, exercising User rights, privacy questions and device data matters: support@borniak.com.
The Controller has not appointed a Data Protection Officer.
2. Scope of the Policy
- The Policy applies to the use of the Borcook App, cloud services, Account, notifications, recipes, Programs, shopping lists, favourites, community features, diagnostics and technical support.
- The purchase of a subscription is made through the BORNIAK online store or another website indicated by BORNIAK. Data processed in connection with the purchase, payment, invoice, automatic renewal and complaints concerning the purchase may also be covered by the privacy policy of the BORNIAK online store.
- The online store account and the Account in the App are separate. The store may process data necessary to purchase and assign a subscription to a Device, but this does not mean that the Store Account is automatically linked with the Account in the App.
- App distribution platforms, such as Google Play and the Apple App Store, may process user data independently, in accordance with their own terms and privacy policies.
3. Categories of data processed
3.1. Account and identification data
- e-mail address,
- first name or profile name, if provided,
- Account identifier in the App,
- Firebase login identifiers or identifiers of another identity provider,
- language, country or region of App use,
- Account creation date, login date and Account security data.
3.2. Device and subscription data
- Device ID, serial number, panel identifier or other technical identifiers,
- Device Activation Date,
- status of the Free Plan or Subscription Plan,
- status of the free 6-month period,
- subscription status, validity period, start and end date,
- information on which Account first added the Device and is the Main Account,
- data necessary to assign the subscription to the Device and to handle an exceptional reset or transfer of the subscription.
3.3. Device operation data and operational data
- Device status,
- temperature, time, operating stage, smoke generator and other parameter settings,
- session history or course, if the function is available,
- events, errors, messages, alarms and technical logs,
- firmware version, panel version, App version and compatibility,
- connectivity parameters such as SSID, signal strength, IP addresses, ports, timestamps, session identifiers and other metadata necessary for connection, NAT traversal, security and diagnostics.
Device operational data, in particular temperature, operating times, statuses, errors and connectivity parameters, are processed primarily to provide the service, ensure safety, diagnostics, compatibility and handle technical reports.
3.4. Technical App data
- type and model of the mobile device,
- operating system and its version,
- App version,
- device language, country or region,
- IP address, session identifiers, error and security logs,
- push token or other identifiers needed to deliver notifications.
3.5. User Content and activity in the App
- User Recipes: names, descriptions, ingredients, steps, photos, notes, parameters and metadata,
- Programs: names, operating parameters, stages, temperatures, times, smoke generator settings and other parameters,
- information on recipes viewed, searched, imported, edited and saved,
- favourites, shopping lists, list items, quantities, completion status and history,
- private shares, User code, sharing relationships and copy information,
- ratings, comments, infringement reports, moderation history and moderation decisions, if these functions are available.
3.6. Payment and subscription purchase data
- order or transaction identifier,
- payment status,
- selected subscription period: monthly or annual,
- information on automatic renewal,
- cancellation status,
- data needed to assign the purchase to a Device.
BORNIAK does not store full payment card details. Card data and payment authorisation are processed by the payment operator or payment service provider.
3.7. Contact and support data
- e-mail address,
- correspondence content,
- description of the problem, report, complaint or question,
- attachments, photos, screenshots, logs and technical data provided by the User,
- case handling history.
4. Purposes and legal bases of processing
| Purpose | Legal basis |
|---|---|
| Creating, maintaining and securing the Account | Article 6(1)(b) GDPR; Article 6(1)(f) GDPR |
| Login via Firebase or another identity provider | Article 6(1)(b) GDPR |
| Adding a Device, determining the Main Account and handling pairing/reset | Article 6(1)(b) GDPR; Article 6(1)(f) GDPR |
| Local control, LAN, hotspot/AP and App function handling | Article 6(1)(b) GDPR |
| Cloud status viewing, cloud control and synchronisation | Article 6(1)(b) GDPR; Article 6(1)(f) GDPR |
| Subscription handling, free period and plan limits | Article 6(1)(b) GDPR; Article 6(1)(c) GDPR; Article 6(1)(f) GDPR |
| Handling payments, orders, invoices and settlements in the store | Article 6(1)(b) GDPR; Article 6(1)(c) GDPR |
| Storage and synchronisation of recipes, Programs, favourites, shopping lists, timers and reminders | Article 6(1)(b) GDPR |
| Private sharing of content with other Users | Article 6(1)(b) GDPR |
| Recipe search, ratings, rankings, comments and community features | Article 6(1)(b) GDPR; Article 6(1)(f) GDPR |
| Storage and moderation of User Content, including recipes, Programs, comments, ratings and reports | Article 6(1)(b) GDPR; Article 6(1)(f) GDPR |
| Moderation, abuse prevention and handling infringement reports | Article 6(1)(f) GDPR; Article 6(1)(c) GDPR where required by law |
| Compliance with product safety obligations, safety communications, service actions and GPSR | Article 6(1)(c) GDPR; Article 6(1)(f) GDPR |
| Diagnostics, logs, network security and error detection | Article 6(1)(b) GDPR; Article 6(1)(f) GDPR |
| Diagnostics and product development, improvement of compatibility, stability, quality and safety of Devices and the App | Article 6(1)(f) GDPR |
| Firebase Analytics, Google Analytics, statistics and App development | Article 6(1)(a) GDPR where consent is required; Article 6(1)(f) GDPR for basic statistics permitted without consent |
| Technical/service push and e-mail notifications | Article 6(1)(b) GDPR; Article 6(1)(f) GDPR |
| Marketing communication, if any | Article 6(1)(a) GDPR and applicable electronic communications laws |
| Complaints, technical support, establishment, pursuit and defence of claims | Article 6(1)(b), (c) and (f) GDPR |
| Exercise of rights under GDPR and the Data Act | Article 6(1)(c) GDPR; Article 6(1)(b) GDPR if the request relates to service performance |
5. Firebase, Google Analytics, Crashlytics and notifications
- The App uses Firebase Authentication for login, authentication and maintenance of the User Account.
- The App may use Firebase Analytics and Google Analytics to analyse use of functions, recipe popularity, effectiveness of App development, service quality improvement and preparation of statistics.
- The App may use Firebase Crashlytics or similar diagnostic tools to detect crashes, errors and compatibility, stability and security problems of the App.
- The App may use Firebase Cloud Messaging, Apple Push Notification service or similar services to deliver technical, service, Device operation, timer and reminder notifications or – if the User gives appropriate consent – marketing communication.
- The scope of data may include App events, information about the mobile device, system version, App version, country, language, interactions with functions, technical identifiers, push token, installation identifiers and basic data about errors and crashes.
- If consent is required for a given category of analytics, non-essential diagnostics or marketing communication, the App will request it separately or allow consent management.
- Lack of consent to non-essential analytics should not block basic use of the App, but may limit personalisation, statistics or improvement of functions based on usage data.
6. Hosting, infrastructure and diagnostics
- The App backend is maintained in AWS infrastructure or with other hosting providers indicated by BORNIAK.
- The diagnostic server is maintained on a separate BORNIAK server in the European Union.
- Diagnostic data is stored in an environment separated from Account data and is not automatically paired with the User Account.
- BORNIAK does not use diagnostic data to identify the User unless this is necessary to handle a service report, complaint, error diagnostics or safety assurance, and the User provides data identifying the Device, in particular Device ID, serial number or other information necessary for diagnostics.
- Device-identifying data provided by the User is used exclusively for handling the report, complaint, error diagnostics or safety assurance.
7. Recipients of data
Data may be disclosed to or entrusted to the following categories of recipients:
- authorised employees and contractors of BORNIAK,
- providers of hosting, cloud infrastructure, databases, monitoring and security, including AWS,
- providers of login, analytics and technical tools, including Firebase and Google Analytics services,
- push notification providers, in particular Google and Apple,
- Google, Apple or other app store operators in connection with downloading, updating, distributing the App, platform account handling, reports and services provided by these platforms,
- payment and online store operators in connection with subscription purchase,
- customer support, e-mail, ticketing and communication tool providers,
- service partners, if necessary to handle a complaint, warranty, repair or support,
- public authorities, courts or other entities authorised by law.
8. Transfers outside the EEA
- Some data may be transferred outside the European Economic Area in connection with the use of global technology providers, in particular Google, Firebase, Apple, AWS or payment operators.
- Where data is transferred outside the EEA, BORNIAK applies appropriate legal safeguards, in particular adequacy decisions, Standard Contractual Clauses, technical and organisational measures or other mechanisms provided for by the GDPR.
- The scope of transfers depends on selected functions, the User’s country, provider configuration and current technical infrastructure.
9. Data retention
| Data category | Retention period |
|---|---|
| User Account | For the period of maintaining the Account, and then for the period necessary to delete data, ensure accountability, security, backups or defence of claims. |
| Recipes, Programs, favourites, shopping lists and other User Content | For the period of maintaining the Account or until deleted by the User, subject to backups, logs and content shared with other Users. |
| Data exceeding Free Plan limits after subscription termination | May remain stored but blocked from use or editing until the Paid Plan is purchased again, or until deleted by the User, if the deletion function is available. |
| Subscription, purchase and settlement data | For the period required by tax, accounting and consumer laws and for the limitation period for claims. |
| Security, error and access logs | Generally up to 12 months, unless a longer period is necessary for an incident, complaint, security or claims. |
| Technical app and compatibility data | Generally up to 24 months or for the period necessary for diagnostics, security improvement and compatibility. |
| Diagnostic data not automatically linked to the Account | Generally up to 12 months, and then in aggregated or anonymised form, unless needed longer for safety, complaints or legal obligations. |
| Timers and reminders | Until performed, cancelled or deleted, and basic delivery and error logs generally up to 90 days. |
| Infringement reports and moderation | For the report handling period and generally up to 12 months for accountability, security and defence of claims, unless the law requires a longer period. |
| Data processed on the basis of consent | Until consent is withdrawn or the purpose is achieved, whichever occurs first. |
10. Data after subscription expiry
- After subscription expiry, User data exceeding Free Plan limits may continue to be stored in the system.
- Functions relating to such data may be blocked, hidden or restricted until the subscription is purchased again.
- After repurchasing a subscription, the User should regain access to previously stored data to the extent technically available and compliant with current plan limits.
11. User rights under the GDPR
The User has the right to:
- access data,
- rectify data,
- erase data,
- restrict processing,
- data portability,
- object to processing based on legitimate interest,
- withdraw consent at any time if processing is based on consent,
- lodge a complaint with the President of the Personal Data Protection Office or the competent supervisory authority.
Requests may be sent to support@borniak.com or submitted directly in the App if BORNIAK provides the relevant function, in particular the function to delete the Account or data. BORNIAK responds to requests without undue delay, generally within one month, with the possibility of extension in cases provided for by the GDPR.
12. Device data and the Data Act
- Data generated by the Device means technical and operational data arising during the use of a compatible Device or its communication with the App and BORNIAK services.
- This data may include in particular: operating settings and profiles, set and measured temperatures, operating times, program stages, smoke generator status, heater or other component status, session course, events, alarms, errors, firmware version, compatibility information, connectivity parameters, technical identifiers and diagnostic data.
- Not all data generated by the Device is personal data. Data may become personal data if it is linked to the User Account, a service report, subscription, Device ID that can be linked to the User, or another identifier that allows a person to be identified.
- The User may ask BORNIAK for access to data generated by the Device or for its export within the scope provided by applicable law, in particular laws concerning data from connected products.
- At the current stage, requests are handled manually by support at support@borniak.com. The request should contain data allowing verification of the User, the Device, the scope of the request and the entitlement to access the data.
- The procedure may include: verification of identity or Account, confirmation of the connection with the Device, determination of the data scope, safety assessment, preparation of export in a technically possible format and provision of data through a secure channel.
- Fulfilment of a request may be restricted or refused if the request is manifestly unfounded, excessive, technically impossible, threatens the security of the Device, network or services, infringes third-party rights, requires disclosure of trade secrets, intellectual property, highly processed data or information protected by law.
13. Automated decisions and profiling
- BORNIAK does not make decisions concerning the User based solely on automated processing that would produce legal effects concerning them or similarly significantly affect them within the meaning of Article 22 GDPR.
- The App may use functional recommendations, popularity statistics, recipe or ingredient suggestions, search filters, content matching to the device, country or popularity, and anti-abuse mechanisms. Such actions are auxiliary and do not produce legal effects or similarly significant effects for the User within the meaning of Article 22 GDPR.
14. Data security
- BORNIAK applies technical and organisational measures intended to protect data against unauthorised access, loss, alteration, disclosure or destruction.
- Measures may include transmission encryption, access control, administrative authentication, backups, monitoring, database segregation, access restrictions and incident response procedures.
- The User should protect their Account, phone, passwords, login methods, access to the Device panel, local network and authorisation codes.
- If unauthorised access to the Account or Device is suspected, the User should contact BORNIAK without delay.
15. Children’s data
- The App is not intended for children under 16 years of age without the consent of their legal representative.
- If BORNIAK determines that it processes a child’s data without the required consent, it will take appropriate steps to delete the data or restrict access to the App.
16. Local storage, cache and local data
- The App may store data locally on the User’s mobile device, in particular cache, settings, session tokens, recently used recipes, offline data or auxiliary data.
- With the User's consent, the Application may securely store the SSID and password of the last used Wi-Fi network on the User's mobile device to simplify future connections with a BORNIAK device. These data are stored only on the device, are not transmitted to BORNIAK servers or shared with third parties, and can be removed by the User at any time.
- Local data is used for proper operation of the App, faster performance, hotspot/AP mode, LAN mode, synchronisation and remembering preferences.
- Deleting the App or local data from the phone may result in the loss of data not synchronised with the backend.
17. Changes to the Privacy Policy
- BORNIAK may amend the Privacy Policy in particular in the event of changes to App functions, technology providers, infrastructure, subscription model, legal provisions or the need to clarify processing rules.
- The User will be informed of material changes in the App, on the website, by e-mail or in another appropriate manner.