Privacy Policy

General Data Protection Regulation (GDPR) Compliant Privacy Notice

Document Version: 2.1 | Last Updated: December 24, 2025 | Effective Date: December 24, 2025

โš–๏ธ Important Legal Notice

This Privacy Policy is prepared in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable data protection laws. Please read this policy carefully before using the Dozi application. By using our services, you acknowledge that you have read and understood this Privacy Policy.

1. Data Controller

For the purposes of the General Data Protection Regulation (GDPR), the data controller responsible for your personal data is:

Data Controller Information

๐Ÿข
Company: Bardino Technology
๐Ÿ“ง
๐ŸŒ
Website: www.dozi.app
๐Ÿ›ก๏ธ
Data Protection Officer: dpo@dozi.app

2. Personal Data We Collect

We collect and process the following categories of personal data when you use the Dozi application:

2.1. Identity and Contact Data

Data Type Description Source
Name First and last name from your Google account Google Sign-In
Email Address Your Google account email Google Sign-In
Profile Picture Profile image from your Google account Google Sign-In
Date of Birth Optional, user-provided User input

2.2. Special Category Data (Health Data)

Data Type Description Purpose
Medication Information Medicine names, dosages, administration methods, barcodes Medication reminder service
Medication History Taken/skipped doses, timestamps Adherence tracking and statistics
Reminder Schedules Medication times and frequencies Timely reminder notifications
Stock Information Remaining medication quantities Low stock alerts
Health Notes User-entered health notes and appointments Activity calendar and health tracking
Health Measurements Blood pressure, glucose, temperature (Premium) Health monitoring and trends

2.3. Technical and Device Data

Data Type Description Purpose
Device Identifier Unique device ID Security, multi-device management
FCM Token Firebase Cloud Messaging token Push notification delivery
IP Address Internet protocol address Security, geographic analysis
Device Information Android version, device model/manufacturer Compatibility, debugging
App Version Dozi application version Support, update notifications
Crash Reports Application error logs Bug fixing, stability improvement

2.4. Location Data (Premium Feature)

๐Ÿ“ Location Data Collection Disclosure

Dozi collects and uses location data to provide location-based medication reminders. This section explains exactly how we access, collect, use, and share your location information.

Data Type Description Purpose Collection Method
Precise GPS Coordinates Real-time latitude and longitude from device GPS Location-based medication reminders (geofencing) Android Location Services API when app is in foreground or background
Saved Locations User-defined places (home, work, pharmacy, etc.) with coordinates Geofence trigger points for reminders User input via Google Maps integration
Geofence Events Entry/exit events when you arrive at or leave saved locations Triggering location-based medication reminders Android Geofencing API

How We Use Location Data

Location Data Storage and Sharing

โ„น๏ธ Location Permission Control

When is location accessed? Location is accessed only when you have enabled location-based reminders for a medication AND granted location permission to the app.

Background Location: To provide reliable location-based reminders, we may access your location in the background. You will be asked for explicit "Allow all the time" permission.

How to disable: You can revoke location permission at any time through your device Settings > Apps > Dozi > Permissions > Location. You can also disable location-based reminders in the app settings.

Premium Only: Location features are available only to Premium subscribers.

2.5. AI Assistant Data

Data Type Description Purpose
Chat History Conversations with the AI assistant Contextual responses, personalization
User Preferences Learned preferences and habits Proactive suggestions, personalization

โœ… AI Data Protection

Your conversations with the AI assistant are not used to train AI models. Chat history is retained for a maximum of 30 days on your device for context purposes and is not shared with third parties.

2.6. Family Tracking Data (Badi System)

Data Type Description Purpose
Badi Connections Family member/caregiver relationships Family tracking system operation
Shared Medication Data Medication and adherence data shared with Badis Escalation notifications, monitoring
Nicknames Privacy-protected display names Privacy-preserving identification

2.7. Payment and Subscription Data

Data Type Description Purpose
Subscription Status Premium/Family plan status Feature access control
Purchase Token Google Play purchase verification token Subscription validation

โœ… Payment Security

We do not collect, process, or store your credit card or banking information. All payment transactions are securely processed through Google Play Store infrastructure.

3. Purposes of Processing

We process your personal data for the following purposes:

3.1. Core Service Delivery

3.2. Account Management

3.3. Premium Services

3.4. Family Tracking System (Badi)

3.5. Communication

3.6. Security and Debugging

3.7. Analytics and Improvement

4. Lawful Basis for Processing

Under Article 6 of the GDPR, we process your personal data based on the following lawful bases:

Lawful Basis GDPR Article Processing Activities
Consent Art. 6(1)(a) Marketing communications, analytics, optional features
Contract Performance Art. 6(1)(b) Account creation, core service delivery, subscription management
Legal Obligation Art. 6(1)(c) Tax records, regulatory compliance, legal requests
Legitimate Interests Art. 6(1)(f) Security measures, fraud prevention, service improvement

4.1. Special Category Data (Health Data)

4.2. Withdrawal of Consent

You have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. To withdraw consent:

4.3. Legitimate Interests Assessment

Where we rely on legitimate interests, we have conducted a balancing test to ensure our interests do not override your fundamental rights and freedoms. Our legitimate interests include:

5. Data Sharing and International Transfers

We may share your personal data with the following categories of recipients:

5.1. Service Providers (Data Processors)

Provider Purpose Location Safeguards
Google Firebase Authentication, database, notifications, analytics USA/EU SCCs, SOC 2, ISO 27001
Google Cloud Platform Server infrastructure, data storage USA/EU SCCs, SOC 2, ISO 27001
Firebase Vertex AI AI assistant service (Gemini) USA DPA, encryption
Google Play Services App distribution, payment processing USA PCI DSS, GDPR compliant

5.2. International Data Transfers

๐ŸŒ Transfer Mechanisms

When we transfer your personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place in accordance with Chapter V of the GDPR:

5.3. Other Recipients

5.4. Data We Never Share

We never sell your personal data. The following data is never shared with third parties:

6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.

Data Category Retention Period Post-Retention Action
Account and Identity Data Duration of account + 30 days after deletion Deletion or anonymization
Health Data (Medications, History) Duration of account + 30 days after deletion Permanent deletion
AI Chat History Last 30 days (on device) Automatic deletion
Location Data Real-time processing only, no persistent storage Immediate deletion after processing
Security and Log Data 2 years Deletion
Support Communications 3 years Deletion or anonymization
Subscription and Payment Records 7 years (legal requirement) Deletion after legal period
Analytics Data 2 years (anonymized) Already anonymized

๐Ÿ—‘๏ธ Account Deletion

When you delete your account, all your personal data will be permanently deleted within 30 days. During this period, you can restore your account. Data subject to legal retention requirements (such as payment records) will be retained until the end of the applicable legal period.

6.1. Criteria for Retention Periods

We determine retention periods based on:

7. Data Security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR.

7.1. Technical Measures

7.2. Organizational Measures

7.3. Data Breach Notification

In the event of a personal data breach, we will:

8. Your Rights Under GDPR

Under the GDPR, you have the following rights regarding your personal data:

8.1. Right of Access (Article 15)

You have the right to obtain confirmation as to whether your personal data is being processed and, if so, access to that data and information about the processing.

8.2. Right to Rectification (Article 16)

You have the right to have inaccurate personal data corrected and incomplete data completed.

8.3. Right to Erasure / "Right to be Forgotten" (Article 17)

You have the right to request deletion of your personal data when:

8.4. Right to Restriction of Processing (Article 18)

You have the right to request restriction of processing when:

8.5. Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and transmit it to another controller.

8.6. Right to Object (Article 21)

You have the right to object to processing based on legitimate interests or for direct marketing purposes.

8.7. Right Not to be Subject to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you.

โœ… Exercising Your Rights In-App

You can exercise many of your rights directly through the app:

  • Settings > Account > Delete Account: Right to erasure
  • Settings > Privacy: Manage data sharing preferences
  • Settings > Download My Data: Right to data portability
  • Profile > Edit: Right to rectification

8.8. How to Exercise Your Rights

To exercise any of your rights, please contact us at:

We will respond to your request within one month. In complex cases, we may extend this by two additional months, and we will inform you of any such extension.

9. Children's Privacy

We are committed to protecting the privacy of children who use our services.

9.1. Age Restrictions

9.2. Parental Rights

Parents and legal guardians have the right to:

9.3. Additional Protections

10. Cookies and Tracking Technologies

Dozi is a native mobile application and does not use cookies. However, we use the following technologies:

10.1. Firebase Analytics

10.2. Firebase Crashlytics

10.3. Local Storage

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

11.1. Notification of Changes

We will notify you of material changes through:

11.2. Effective Date

Changes will take effect 30 days after notification. Continued use of the app after this period constitutes acceptance of the changes. If you do not agree with the changes, you may delete your account.

Document Version: 2.0
Last Updated: December 23, 2025
Effective Date: December 23, 2025
Previous Version: 1.0 (December 8, 2025)

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:

Data Controller Contact Information

๐Ÿข
Company: Bardino Technology
๐Ÿ“ง
Privacy Email: privacy@dozi.app
๐Ÿ›ก๏ธ
Data Protection Officer: dpo@dozi.app
๐ŸŒ
Website: www.dozi.app

13. Right to Lodge a Complaint

Under Article 77 of the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

13.1. EU Supervisory Authorities

You can find your local data protection authority at:

13.2. Turkish Data Protection Authority

For users in Turkey, you may also contact:

KiลŸisel Verileri Koruma Kurumu (KVKK)

๐Ÿ›๏ธ
Address: Nasuh Akar Mah. Ziyabey Cad. 1407. Sok. No: 4, 06520 Balgat-ร‡ankaya/Ankara, Turkey
๐Ÿ“ž
Phone: +90 312 216 50 50
๐ŸŒ