Privacy Policy - Zamnesia Grow Control App
Last updated: 25 May 2026
Version: 1.0
1. Who We Are
This Privacy Policy explains how we collect, use, and protect your personal data when you use the Zamnesia Grow Control App.
Data Controller:
Just Amazing BV
Trading as: Zamnesia
KvK: 54983045
VAT: NL851516166B01
Address: Lorentzweg 7, 5482 TP Schijndel, The Netherlands
Phone: +31 (0)20 722 07 17
Contact: https://zamnesia.zendesk.com/hc/en-001/requests/new
2. What Data We Collect
2.1. Account Data
| Data | Purpose | When collected |
|---|---|---|
| Email address | Account creation, login, password reset, communications | Registration |
| Password (hashed) | Authentication | Registration |
| Display name (optional) | Personalization | Profile setup |
| Device name(s) you assign | Device identification within the App | Device setup |
2.2. Device & Sensor Data
| Data | Purpose | When collected |
|---|---|---|
Device ID (zamnesia-grow-XXXX) |
Identify and communicate with your controller | Device setup |
| MAC address | Device identification during BLE provisioning | Device setup |
| Temperature readings | Display in App, trigger automations/alerts | Continuously, in real time |
| Humidity readings | Display in App, trigger automations/alerts | Continuously, in real time |
| Channel states (on/off, speed, dimming %) | Display current device state, history | On each change |
| Schedule/timer configurations | Store and sync your automation settings | On each change |
| Firmware version | Display in App, check for updates | On device boot |
| Device online/offline status | Display connectivity status | On each change |
| Error events | Diagnostics, support | On occurrence |
2.3. Network & Provisioning Data
| Data | Purpose | When collected |
|---|---|---|
| WiFi SSID | Display connected network, setup flow | During provisioning |
| WiFi password | Sent to device during BLE setup - not stored by us | During provisioning only |
| IP address | Server communication, security | Each API/MQTT connection |
2.4. App Usage Data
| Data | Purpose | When collected |
|---|---|---|
| App version | Compatibility, support | On app launch |
| Operating system & device type | Compatibility, support, crash diagnostics | On app launch |
| Crash reports (if enabled) | Bug fixing, stability improvement | On crash |
2.5. Data We Do NOT Collect
- Location data (GPS)
- Contacts or address book
- Photos, camera, or microphone data
- Financial or payment data (App Store/Google Play handle payments)
- Dutch citizen service number (BSN)
- Health data or biometric data
3. Why We Process Your Data & Our Legal Basis
Under the GDPR, we need a legal basis for each processing activity:
| Processing activity | Legal basis (GDPR Art. 6) | Details |
|---|---|---|
| Account creation & authentication | Contract performance (Art. 6(1)(b)) | Necessary to provide you with the service |
| Device setup & provisioning (BLE/WiFi) | Contract performance (Art. 6(1)(b)) | Necessary to connect your device |
| Sensor data collection & display | Contract performance (Art. 6(1)(b)) | Core functionality of the App |
| Storing schedules & automations | Contract performance (Art. 6(1)(b)) | Core functionality of the App |
| Sending notifications & alerts | Contract performance (Art. 6(1)(b)) | Feature you enable in the App |
| Password reset emails | Contract performance (Art. 6(1)(b)) | Necessary to maintain account access |
| Technical support (accessing device data when you contact us) | Contract performance (Art. 6(1)(b)) | Necessary to diagnose and resolve issues |
| Firmware update delivery | Legitimate interest (Art. 6(1)(f)) | Keeping your device secure and functional |
| Crash reports & diagnostics | Legitimate interest (Art. 6(1)(f)) | Improving app stability and fixing bugs |
| Security monitoring (abuse detection) | Legitimate interest (Art. 6(1)(f)) | Protecting the service and other users |
| Service announcements (e.g., outages) | Legitimate interest (Art. 6(1)(f)) | Informing you about service-affecting events |
We do not process your data based on consent for any core functionality. If we introduce optional features that require consent (e.g., analytics, marketing), we will ask for your explicit consent separately, and you can withdraw it at any time.
4. Who Has Access to Your Data
4.1. Within Just Amazing BV
Only authorized personnel have access to personal data, limited to what is necessary for their role:
| Role | Access |
|---|---|
| Customer support | Account data, device status - only when you contact us |
| Development team | Anonymized/aggregated diagnostics and crash reports |
4.2. Third-Party Processors
We use the following third-party service providers who process data on our behalf:
| Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| Amazon Web Services (AWS) | MQTT broker (iot.zamnesia.io), API hosting, data storage |
EU (eu-west-1, Ireland) | Data Processing Agreement |
| Splio (splio.com) | Account verification, password reset, and service notification emails (via Splio SMTP relay) | EU (France) | Data Processing Agreement |
| Apple Inc. & Google LLC (App Store / Google Play) | Independent controllers for app distribution and account management on their respective platforms. Their own privacy policies apply to App Store / Play Store account data. | USA | EU-US Data Privacy Framework |
| Apple / Google diagnostic services (only if enabled) | Processor for crash reporting and performance diagnostics related to the App | USA | EU-US Data Privacy Framework |
We have Data Processing Agreements (DPAs) in place with all third-party processors.
4.3. We Do NOT
- Sell your personal data to third parties
- Share your data with advertisers
- Use your data for profiling or automated decision-making
- Transfer your data outside the EU/EEA without appropriate safeguards (Standard Contractual Clauses or an adequacy decision)
5. How Long We Keep Your Data
| Data category | Retention period |
|---|---|
| Account data | Until you delete your account |
| Sensor readings (temperature, humidity) | 12 months rolling |
| Error/event logs | 6 months rolling |
| Device status & channel history | 12 months rolling |
| Schedule configurations | Until you delete them or your account |
| Crash reports | 6 months |
| WiFi SSID | Until you unlink your device or delete your account |
| MAC address (controller) | While the device is linked to your account |
| Server/security logs (IP addresses) | 3 months |
After the retention period, data is automatically and permanently deleted.
When you delete your account, all your personal data and associated device data is permanently erased within 30 days.
6. How We Protect Your Data
| Measure | Details |
|---|---|
| Encryption in transit | TLS 1.2+ for all API and MQTT communication |
| Encryption at rest | Database encryption on cloud servers |
| Authentication | JWT tokens with expiration; passwords stored using bcrypt hashing |
| BLE provisioning | Encrypted BluFi protocol |
| WiFi credentials | Sent directly to device via BLE - never stored on our servers |
| Access control | Role-based access; principle of least privilege |
| Monitoring | Automated alerts for unauthorized access attempts |
7. Your Rights Under the GDPR
You have the following rights regarding your personal data:
| Right | What it means | How to exercise |
|---|---|---|
| Access (Art. 15) | Request a copy of all personal data we hold about you | Submit a request via https://zamnesia.zendesk.com/hc/en-001/requests/new, or use in-app data export |
| Rectification (Art. 16) | Correct inaccurate data | Update in the App, or submit a request via https://zamnesia.zendesk.com/hc/en-001/requests/new |
| Erasure (Art. 17) | Request deletion of your data ("right to be forgotten") | Delete your account in the App, or submit a request via https://zamnesia.zendesk.com/hc/en-001/requests/new |
| Restriction (Art. 18) | Restrict processing while a dispute is being resolved | Submit a request via https://zamnesia.zendesk.com/hc/en-001/requests/new |
| Data portability (Art. 20) | Receive your data in a structured, machine-readable format (JSON/CSV) | Use in-app data export, or submit a request via https://zamnesia.zendesk.com/hc/en-001/requests/new |
| Objection (Art. 21) | Object to processing based on legitimate interest | Submit a request via https://zamnesia.zendesk.com/hc/en-001/requests/new |
| Withdraw consent | Withdraw consent at any time (where consent is the legal basis) | In-app settings, or submit a request via https://zamnesia.zendesk.com/hc/en-001/requests/new |
We will respond to your request within 30 days. If we need more time (up to 60 additional days for complex requests), we will inform you within the initial 30-day period.
Exercising your rights is free of charge, unless requests are manifestly unfounded or excessive.
8. Your Rights Under the EU Data Act
In addition to your GDPR rights, the EU Data Act (Regulation 2023/2854) gives you specific rights regarding data generated by your connected Zamnesia controller:
- Access: You can access all data generated by your device at any time, free of charge, via the App
- Export: You can download your data in JSON or CSV format via Settings > Export Data
- Share: You can request that we share your device data with a third party of your choosing - submit a request via https://zamnesia.zendesk.com/hc/en-001/requests/new
- Delete: You can delete your device data via the App or by deleting your account
9. Children's Privacy
9.1. The App is not intended for users under 18 years of age. This is consistent with our broader brand policy and ensures full contractual capacity under Dutch civil law (Article 1:234 of the Burgerlijk Wetboek). By creating an account, you confirm that you are at least 18 years old.
9.2. For data processing purposes, the age of digital consent under Article 8 of the GDPR (as implemented in Article 5 of the Dutch UAVG) is 16. We do not knowingly collect personal data from anyone under that threshold.
9.3. If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us via https://zamnesia.zendesk.com/hc/en-001/requests/new. We will promptly delete such data.
10. International Data Transfers
10.1. Your data is primarily stored and processed within the European Union / European Economic Area (EU/EEA).
10.2. Where data is transferred outside the EU/EEA (e.g., to service providers in the USA), we ensure an adequate level of protection through:
- The EU-US Data Privacy Framework (for certified US companies), or
- Standard Contractual Clauses (SCCs) approved by the European Commission
10.3. You can request a copy of the applicable transfer safeguards by submitting a request via https://zamnesia.zendesk.com/hc/en-001/requests/new.
11. Cookies & Local Storage
11.1. The App does not use cookies.
11.2. The App stores the following data locally on your device:
| Data | Purpose | Legal basis |
|---|---|---|
| Authentication token (JWT) | Keep you logged in | Strictly necessary |
| MQTT credentials | Maintain connection to your device | Strictly necessary (stored in Android Keystore / iOS Keychain) |
| User preferences (temperature unit, notification settings) | Personalization | Strictly necessary |
| Cached sensor data | Offline viewing | Strictly necessary |
This local storage is strictly necessary for the App to function and does not require consent under Article 5(3) of the ePrivacy Directive.
12. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on you (Article 22 GDPR).
The App's automation features (schedules, temperature thresholds, cycle timers) are configured entirely by you and executed locally on your device. These are user-controlled device commands, not automated personal data processing.
13. Changes to This Privacy Policy
13.1. We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 30 days before they take effect.
13.2. The "Last updated" date at the top of this page indicates the most recent revision.
13.3. We encourage you to review this Privacy Policy periodically.
14. Complaints
If you believe we are processing your data unlawfully or have not adequately addressed your request, you have the right to lodge a complaint with the Dutch Data Protection Authority:
Autoriteit Persoonsgegevens (AP)
Website: https://www.autoriteitpersoonsgegevens.nl
Phone: +31 (0)88 1805 250
Address: Bezuidenhoutseweg 30, 2594 AV Den Haag, The Netherlands
You also have the right to lodge a complaint with the supervisory authority of your country of residence, if different.
15. Contact Us
For any questions about this Privacy Policy or to exercise your rights:
Just Amazing BV
Contact: https://zamnesia.zendesk.com/hc/en-001/requests/new
Phone: +31 (0)20 722 07 17
Address: Lorentzweg 7, 5482 TP Schijndel, The Netherlands
We are not required to appoint a Data Protection Officer (DPO) under Article 37 of the GDPR, as our processing activities do not meet the mandatory designation criteria (we do not carry out large-scale processing of special categories of data, nor large-scale systematic monitoring of data subjects). Privacy queries are handled by our compliance team and can be submitted via the contact channel above.