Privacy Policy
(As of: January 2026)
1. Responsible Party
Responsible for data processing under the General Data Protection Regulation (GDPR) is:
tio health UG (limited liability) Holsteinische Str. 34 10717 Berlin
Email: privacy@tiohealth.care
A data protection officer is not currently appointed.
2. General Information
Protecting your personal data, especially sensitive health data of children, is our top priority. We process personal data solely in accordance with the General Data Protection Regulation (GDPR) and applicable national data protection laws.
The app is intended exclusively for adult parents or guardians. Children do not use the app themselves and are not directly addressed.
3. Data Processing When Visiting the Website
3.1 Server Log Files
When you visit our website, our hosting provider (STRATO AG) automatically collects and stores information in so-called server log files:
- IP address (anonymized)
- Date and time of access
- Browser type/version
- Operating system
- Referrer URL
- Hostname of the accessing computer
These data are technically necessary to correctly provide the website and are not merged with other data sources.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in the technically error-free presentation).
3.2 Contact Form / Registration
If you register for the app or contact us via our contact form, we process the data you provide (e.g., name, email address, child's age).
The processing is solely for handling your request or registration.
Legal basis: Art. 6 para. 1 lit. b GDPR (pre-contractual measure).
3.3 Email Contact
When contacting us by email, we process your information to handle the inquiry.
Legal basis: Art. 6 para. 1 lit. b or lit. f GDPR.
4. Cookies and Tracking
4.1 Google Analytics
We use Google Analytics (Google Ireland Ltd.) to analyze website usage.
- Cookies are set to track your usage behavior (e.g., pages visited, duration, clicks).
- The IP address is anonymized (IP masking).
- Data may be transferred to the USA. Protection is ensured through EU standard contractual clauses.
- Processing occurs only with your consent via our cookie banner.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent).
You can withdraw your consent at any time via the "Cookie Settings."
More information: Google Privacy Notice.
4.2 Brevo (Newsletter / Email Communication)
For email communication and newsletters, we use the service Brevo (Sendinblue GmbH, Berlin).
- Brevo acts as a data processor.
- Data (e.g., email address, name) is stored on servers in the EU.
- There is a data processing agreement (DPA) and sub-processor regulations.
- You can withdraw your consent to receive emails at any time (e.g., via unsubscribe link).
Legal basis: Art. 6 para. 1 lit. a GDPR (consent).
More info: Brevo Privacy.
4.3 Cookie Yes (Consent Management)
We use the consent management tool CookieYes to manage your consents for storing certain cookies and using analytics and tracking technologies.
The following data is processed:
- Your given or withdrawn consent,
- Time of decision,
- An anonymous key (Consent ID),
- Possibly other technical metadata.
This information is stored in a technically necessary cookie so that the website can remember your cookie settings on future visits.
Legal basis: Art. 6 para. 1 lit. c GDPR (legal obligation for data protection-compliant consent management).
More info: Cookie Yes Privacy
5. Sub-Processors
Our processors (Brevo, Google/Firebase) partly use sub-processors. An up-to-date list can be found on the providers' websites. We ensure that appropriate contracts (DPA, SCCs) are in place.
6. Rights of Data Subjects
You have the right at any time to:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction (Art. 18 GDPR)
- Data Portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Withdrawal of Consent (Art. 7 Para. 3 GDPR)
- Complaint to a Supervisory Authority (Art. 77 GDPR)
7. Hosting
Our website is hosted by STRATO AG, Berlin.
A data processing agreement is in place.
8. Security
We use technical and organizational measures (TOMs) to protect your data from loss, misuse, or unauthorized access, including encryption, SSL, access restrictions, and regular security audits.
9. Updates
We reserve the right to update this privacy policy in case of changes to the app or website.