Privacy Policy
Last updated: March 20, 20261. Introduction
ABASAM (“we”, “our”, or “us”) is committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws. This Privacy Policy explains how we collect, use, store, and safeguard your personal data when you use the ABASAM mobile application.
2. Data Controller
ABASAM acts as the data controller for the personal data collected through this application. For any questions regarding data processing, contact us at: hello@abasam-app.com
3. Legal Basis for Processing
We process your personal data based on the following legal grounds under GDPR Article 6:
- Consent (Art. 6(1)(a)): You provide explicit consent when creating an account and agreeing to this Privacy Policy.
- Contract Performance (Art. 6(1)(b)): Processing is necessary to provide you with our document translation and analysis services.
- Legitimate Interests (Art. 6(1)(f)): We may process data to improve our services and ensure security, where this does not override your rights.
4. Information We Collect
Account Information: When you create an account, we collect your name and email address. Your password is securely hashed using industry-standard algorithms and never stored in plain text.
Documents: When you scan or upload documents, the images are processed through our secure servers for analysis. We do not permanently store the original images on our servers after analysis is complete. Document images are processed in-memory and immediately discarded.
Vault Data: Translated summaries, action items, and deadlines are stored securely in your personal vault, encrypted with AES-256 and protected by Row Level Security — only you can access your data.
Preferences: Language preferences, notification settings, and app configuration are stored locally on your device and in your profile.
Consent Records: We maintain records of when and how you provided consent for data processing.
5. How We Use Your Information
- To provide document analysis and translation services
- To store your translated documents in your encrypted personal vault
- To send configurable deadline reminders via local notifications (with your consent)
- To maintain and improve the quality of our services
- To communicate important service updates
- To comply with legal obligations
6. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- AES-256 encryption for all vault data at rest, with keys stored in hardware-backed secure storage
- 256-bit encryption keys generated using a cryptographically secure random number generator (CSPRNG)
- Encrypted data transmission via HTTPS/TLS 1.3 for all network communication
- Row Level Security (RLS) for complete database isolation between users
- Secure authentication via Supabase Auth with bcrypt-hashed passwords
- Optional PIN and biometric app lock for additional device-level protection
7. Third-Party Services (Data Processors)
We use the following third-party services as data processors. Each has been vetted for GDPR compliance:
- Google Gemini AI — Document analysis and translation. Data is processed in accordance with Google’s AI data processing terms and is not used to train models.
- Supabase — Authentication and secure data storage. EU-based data centers available. Compliant with GDPR and SOC 2 Type II certified.
- RevenueCat — Subscription management. Processes only subscription-related data necessary for payment processing.
We have Data Processing Agreements (DPAs) in place with all processors.
8. International Data Transfers
Some of our service providers may process data outside the European Economic Area (EEA). When this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.
9. Data Retention
- Account Data: Retained while your account is active and deleted immediately when you request account deletion through the app.
- Vault Documents: Retained until you delete them or delete your account.
- Scanned Images: Processed in real-time and immediately discarded; not stored.
- Consent Records: Retained for 5 years after consent withdrawal for legal compliance.
10. Your Rights Under GDPR
Under GDPR, you have the following rights regarding your personal data:
- Right to Access (Art. 15): Request a copy of all personal data we hold about you. Use the “Export My Data” feature in Settings.
- Right to Rectification (Art. 16): Request correction of inaccurate personal data.
- Right to Erasure (Art. 17): Request deletion of your personal data (“right to be forgotten”). Use the “Delete My Account” feature in Settings.
- Right to Restrict Processing (Art. 18): Request limitation of processing in certain circumstances.
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests.
- Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at hello@abasam-app.com or use the in-app features in Settings → Data & Privacy.
11. Automated Decision-Making
Our document analysis uses AI to extract and translate information. This processing does not make decisions that significantly affect you, is necessary for providing the service you requested, and can be reviewed manually upon request.
12. Children’s Privacy
ABASAM is not intended for children under 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.
13. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and notify affected users without undue delay if the breach poses a high risk.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes via in-app notification or email to your registered address. Continued use of the app after changes constitutes acceptance of the updated policy.
15. Supervisory Authority
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with your local data protection supervisory authority. For users in the EU, you can find your local authority at: edpb.europa.eu/about-edpb/board/members_en
16. Contact Us
For any questions about this Privacy Policy or to exercise your data protection rights:
Email: hello@abasam-app.com
We aim to respond to all requests within 30 days.