Privacy Policy - Zamnesia Grow Control App

Last updated: 25 May 2026
Version: 1.0


1. Who We Are

This Privacy Policy explains how we collect, use, and protect your personal data when you use the Zamnesia Grow Control App.

Data Controller:
Just Amazing BV
Trading as: Zamnesia
KvK: 54983045
VAT: NL851516166B01
Address: Lorentzweg 7, 5482 TP Schijndel, The Netherlands
Phone: +31 (0)20 722 07 17
Contact: https://zamnesia.zendesk.com/hc/en-001/requests/new


2. What Data We Collect

2.1. Account Data

Data Purpose When collected
Email address Account creation, login, password reset, communications Registration
Password (hashed) Authentication Registration
Display name (optional) Personalization Profile setup
Device name(s) you assign Device identification within the App Device setup

2.2. Device & Sensor Data

Data Purpose When collected
Device ID (zamnesia-grow-XXXX) Identify and communicate with your controller Device setup
MAC address Device identification during BLE provisioning Device setup
Temperature readings Display in App, trigger automations/alerts Continuously, in real time
Humidity readings Display in App, trigger automations/alerts Continuously, in real time
Channel states (on/off, speed, dimming %) Display current device state, history On each change
Schedule/timer configurations Store and sync your automation settings On each change
Firmware version Display in App, check for updates On device boot
Device online/offline status Display connectivity status On each change
Error events Diagnostics, support On occurrence

2.3. Network & Provisioning Data

Data Purpose When collected
WiFi SSID Display connected network, setup flow During provisioning
WiFi password Sent to device during BLE setup - not stored by us During provisioning only
IP address Server communication, security Each API/MQTT connection

2.4. App Usage Data

Data Purpose When collected
App version Compatibility, support On app launch
Operating system & device type Compatibility, support, crash diagnostics On app launch
Crash reports (if enabled) Bug fixing, stability improvement On crash

2.5. Data We Do NOT Collect


Under the GDPR, we need a legal basis for each processing activity:

Processing activity Legal basis (GDPR Art. 6) Details
Account creation & authentication Contract performance (Art. 6(1)(b)) Necessary to provide you with the service
Device setup & provisioning (BLE/WiFi) Contract performance (Art. 6(1)(b)) Necessary to connect your device
Sensor data collection & display Contract performance (Art. 6(1)(b)) Core functionality of the App
Storing schedules & automations Contract performance (Art. 6(1)(b)) Core functionality of the App
Sending notifications & alerts Contract performance (Art. 6(1)(b)) Feature you enable in the App
Password reset emails Contract performance (Art. 6(1)(b)) Necessary to maintain account access
Technical support (accessing device data when you contact us) Contract performance (Art. 6(1)(b)) Necessary to diagnose and resolve issues
Firmware update delivery Legitimate interest (Art. 6(1)(f)) Keeping your device secure and functional
Crash reports & diagnostics Legitimate interest (Art. 6(1)(f)) Improving app stability and fixing bugs
Security monitoring (abuse detection) Legitimate interest (Art. 6(1)(f)) Protecting the service and other users
Service announcements (e.g., outages) Legitimate interest (Art. 6(1)(f)) Informing you about service-affecting events

We do not process your data based on consent for any core functionality. If we introduce optional features that require consent (e.g., analytics, marketing), we will ask for your explicit consent separately, and you can withdraw it at any time.


4. Who Has Access to Your Data

4.1. Within Just Amazing BV

Only authorized personnel have access to personal data, limited to what is necessary for their role:

Role Access
Customer support Account data, device status - only when you contact us
Development team Anonymized/aggregated diagnostics and crash reports

4.2. Third-Party Processors

We use the following third-party service providers who process data on our behalf:

Provider Purpose Location Safeguards
Amazon Web Services (AWS) MQTT broker (iot.zamnesia.io), API hosting, data storage EU (eu-west-1, Ireland) Data Processing Agreement
Splio (splio.com) Account verification, password reset, and service notification emails (via Splio SMTP relay) EU (France) Data Processing Agreement
Apple Inc. & Google LLC (App Store / Google Play) Independent controllers for app distribution and account management on their respective platforms. Their own privacy policies apply to App Store / Play Store account data. USA EU-US Data Privacy Framework
Apple / Google diagnostic services (only if enabled) Processor for crash reporting and performance diagnostics related to the App USA EU-US Data Privacy Framework

We have Data Processing Agreements (DPAs) in place with all third-party processors.

4.3. We Do NOT


5. How Long We Keep Your Data

Data category Retention period
Account data Until you delete your account
Sensor readings (temperature, humidity) 12 months rolling
Error/event logs 6 months rolling
Device status & channel history 12 months rolling
Schedule configurations Until you delete them or your account
Crash reports 6 months
WiFi SSID Until you unlink your device or delete your account
MAC address (controller) While the device is linked to your account
Server/security logs (IP addresses) 3 months

After the retention period, data is automatically and permanently deleted.

When you delete your account, all your personal data and associated device data is permanently erased within 30 days.


6. How We Protect Your Data

Measure Details
Encryption in transit TLS 1.2+ for all API and MQTT communication
Encryption at rest Database encryption on cloud servers
Authentication JWT tokens with expiration; passwords stored using bcrypt hashing
BLE provisioning Encrypted BluFi protocol
WiFi credentials Sent directly to device via BLE - never stored on our servers
Access control Role-based access; principle of least privilege
Monitoring Automated alerts for unauthorized access attempts

7. Your Rights Under the GDPR

You have the following rights regarding your personal data:

Right What it means How to exercise
Access (Art. 15) Request a copy of all personal data we hold about you Submit a request via https://zamnesia.zendesk.com/hc/en-001/requests/new, or use in-app data export
Rectification (Art. 16) Correct inaccurate data Update in the App, or submit a request via https://zamnesia.zendesk.com/hc/en-001/requests/new
Erasure (Art. 17) Request deletion of your data ("right to be forgotten") Delete your account in the App, or submit a request via https://zamnesia.zendesk.com/hc/en-001/requests/new
Restriction (Art. 18) Restrict processing while a dispute is being resolved Submit a request via https://zamnesia.zendesk.com/hc/en-001/requests/new
Data portability (Art. 20) Receive your data in a structured, machine-readable format (JSON/CSV) Use in-app data export, or submit a request via https://zamnesia.zendesk.com/hc/en-001/requests/new
Objection (Art. 21) Object to processing based on legitimate interest Submit a request via https://zamnesia.zendesk.com/hc/en-001/requests/new
Withdraw consent Withdraw consent at any time (where consent is the legal basis) In-app settings, or submit a request via https://zamnesia.zendesk.com/hc/en-001/requests/new

We will respond to your request within 30 days. If we need more time (up to 60 additional days for complex requests), we will inform you within the initial 30-day period.

Exercising your rights is free of charge, unless requests are manifestly unfounded or excessive.


8. Your Rights Under the EU Data Act

In addition to your GDPR rights, the EU Data Act (Regulation 2023/2854) gives you specific rights regarding data generated by your connected Zamnesia controller:


9. Children's Privacy

9.1. The App is not intended for users under 18 years of age. This is consistent with our broader brand policy and ensures full contractual capacity under Dutch civil law (Article 1:234 of the Burgerlijk Wetboek). By creating an account, you confirm that you are at least 18 years old.

9.2. For data processing purposes, the age of digital consent under Article 8 of the GDPR (as implemented in Article 5 of the Dutch UAVG) is 16. We do not knowingly collect personal data from anyone under that threshold.

9.3. If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us via https://zamnesia.zendesk.com/hc/en-001/requests/new. We will promptly delete such data.


10. International Data Transfers

10.1. Your data is primarily stored and processed within the European Union / European Economic Area (EU/EEA).

10.2. Where data is transferred outside the EU/EEA (e.g., to service providers in the USA), we ensure an adequate level of protection through:

10.3. You can request a copy of the applicable transfer safeguards by submitting a request via https://zamnesia.zendesk.com/hc/en-001/requests/new.


11. Cookies & Local Storage

11.1. The App does not use cookies.

11.2. The App stores the following data locally on your device:

Data Purpose Legal basis
Authentication token (JWT) Keep you logged in Strictly necessary
MQTT credentials Maintain connection to your device Strictly necessary (stored in Android Keystore / iOS Keychain)
User preferences (temperature unit, notification settings) Personalization Strictly necessary
Cached sensor data Offline viewing Strictly necessary

This local storage is strictly necessary for the App to function and does not require consent under Article 5(3) of the ePrivacy Directive.


12. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on you (Article 22 GDPR).

The App's automation features (schedules, temperature thresholds, cycle timers) are configured entirely by you and executed locally on your device. These are user-controlled device commands, not automated personal data processing.


13. Changes to This Privacy Policy

13.1. We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 30 days before they take effect.

13.2. The "Last updated" date at the top of this page indicates the most recent revision.

13.3. We encourage you to review this Privacy Policy periodically.


14. Complaints

If you believe we are processing your data unlawfully or have not adequately addressed your request, you have the right to lodge a complaint with the Dutch Data Protection Authority:

Autoriteit Persoonsgegevens (AP)
Website: https://www.autoriteitpersoonsgegevens.nl
Phone: +31 (0)88 1805 250
Address: Bezuidenhoutseweg 30, 2594 AV Den Haag, The Netherlands

You also have the right to lodge a complaint with the supervisory authority of your country of residence, if different.


15. Contact Us

For any questions about this Privacy Policy or to exercise your rights:

Just Amazing BV
Contact: https://zamnesia.zendesk.com/hc/en-001/requests/new
Phone: +31 (0)20 722 07 17
Address: Lorentzweg 7, 5482 TP Schijndel, The Netherlands

We are not required to appoint a Data Protection Officer (DPO) under Article 37 of the GDPR, as our processing activities do not meet the mandatory designation criteria (we do not carry out large-scale processing of special categories of data, nor large-scale systematic monitoring of data subjects). Privacy queries are handled by our compliance team and can be submitted via the contact channel above.