← Back to Frezzy

Frezzy privacy policy

This policy explains data processing in the Frezzy app and its associated services. Browsing the landing page and using the app are described separately.

01. Controller and contact

Data controller: DIAPLE NETWORKING, S.L. · Spanish tax ID: B99231631 · Address: Paseo Mª Agustín 4-6, 1ª Planta, Oficina 11, Edificio EBROSA, 50004 Zaragoza, España · Data-rights contact: rgpd@diaple.com · Telephone: +34 976 36 19 63.

Diaple Labs names the initiative presenting Frezzy; it is not identified here as a separate legal entity.

02. Information processed

Account and access: account identifiers, sessions, recovery credentials and linked devices, depending on the access mechanism enabled. Household: household identifiers, members, roles and invitations.

Inventory: food names, dates, quantities, storage locations, logical NFC/QR label identifiers and operation history. This information may be linked to an account or household.

Support: the app does not store email addresses associated with accounts. We process only the addresses and content of emails you voluntarily send to support. Technical information: data needed to serve requests, synchronise and protect the service, including operational events and connection data.

03. Purposes and legal bases

The proposed basis for managing accounts, households, labels, inventory and synchronisation is performance of the service requested by the user.

Security, abuse prevention and technical incident handling are proposed to rely on legitimate interests in protecting the service and its users, subject to an assessment of necessity, proportionality and the rights affected.

Enquiries are handled to respond to a request, manage the service relationship or take pre-contractual steps, depending on their content. Processing required by law relies on the relevant legal obligation.

Optional features or processing requiring consent must be explained and enabled separately. A technical device permission does not by itself replace privacy information or determine the legal basis.

04. Device permissions and operation

Camera: used in the QR-scanning flow when you request it. NFC: used to read or link compatible labels. Applicable permissions can be managed in the operating system.

The mobile app keeps local information so you can view and update inventory offline. Relevant changes synchronise with the service when a connection is available. Invitations and web access are not equivalent to the mobile app’s offline mode.

If dictation is enabled, microphone and speech-recognition access, the provider involved and whether audio leaves the device must be explained.

05. Households and shared access

Authorised household members access shared information according to their roles. Sharing a household means other members can see the entries and changes permitted by the service.

Labels provide a way to access service information, not an invitation to make the inventory public. Protect links and codes that can link devices. Do not send credentials, recovery codes or complete labels to support.

06. Providers, recipients and transfers

Infrastructure, storage and enquiry-handling providers may be involved in delivering the service under the relevant contractual arrangements. Data may also be disclosed when legally required.

The configured pilot backend uses Cloudflare Workers and D1. The project does not establish here the contracting entity, processing regions, subprocessors or transfer safeguards that apply to the published service.

07. How long data is retained

From receipt of the deletion request, the account becomes inactive and its active data is deleted or anonymised within a maximum of seven days. Isolated backups are purged on day 30 from receipt of the request and are not used to reactivate the account unless you request it. Technical logs are retained for one month from generation, and emails sent to support for one month from receipt.

If other household members remain, shared household data stays in place and ownership is transferred to another member. When all members delete their accounts, household data is also deleted or anonymised.

08. The landing page, cookies and external links

The code supplied for this landing page contains no registration forms, first-party cookies, advertising, tracking pixels, remotely loaded fonts or analytics tools. The language selector uses links and stores no browser preference.

The hosting infrastructure may process connection and security data. Any site-wide processing added by Diaple Labs must be reflected in its privacy information and, where relevant, its consent management.

Opening an app store or using email involves external services governed by their own terms.

09. Your rights and how to exercise them

You may request access, rectification, erasure, restriction, portability and objection where provided by applicable law. Where processing relies on consent, you may withdraw it without affecting the lawfulness of earlier processing.

Send your request to rgpd@diaple.com and identify the service as Frezzy. Additional identity information should only be requested when necessary and proportionate. Do not include passwords or recovery codes.

You may also complain to the Spanish Data Protection Agency or the competent supervisory authority. Requests must be handled within the applicable legal time limits.

10. Deleting an account and its data

Deletion is initiated from the account deletion option in the app. From receipt of the request, the account becomes inactive and its active data is deleted or anonymised within a maximum of seven days. Isolated backups are purged on day 30 from receipt of the request and are not used to reactivate the account unless you request it. Technical logs are retained for one month from generation, and emails sent to support for one month from receipt.

If other household members remain, shared household data stays in place and ownership is transferred to another member. If all members delete their accounts, household data is also deleted or anonymised. Uninstalling the app does not delete data from the remote service.

11. Security, children and automated decisions

The technical design includes access controls and protections for storage, synchronisation and credentials. The actual measures must be checked in production; no absolute guarantee or end-to-end-encryption claim is made.

Frezzy is presented as a household organisation tool. Avoid entering sensitive data or unnecessary personal information about other people.

12. Changes and scope of this version

The final policy must state its effective date and be updated when processing changes. Material changes should be communicated through an appropriate channel before new processing where required.

This document is not Apple’s App Privacy form or Google Play’s Data safety section. Those declarations must be completed using the same actual data flows, including integrated providers.