← All legal documents · Privacy Policy · Children's Privacy Notice

Balance — European Union and European Economic Area Country Annex

Effective date: 28 June 2026 Last updated: 28 June 2026

Owner: , Director, BabaYaga Program, TOO — also acts as Privacy Officer and Designated Child Safety Officer for all EU/EEA residents covered by this Annex. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to the EU General Data Protection Regulation (Regulation (EU) 2016/679) or any directly applicable EU successor instrument, (b) any European Data Protection Board ("EDPB") guideline, opinion, or binding decision that materially alters the application of the GDPR to a parental-control service, (c) any change to a Member State's national derogation from Article 8(1) GDPR (the "age of digital consent"), (d) any litigation outcome of the Court of Justice of the European Union ("CJEU") that materially changes the validity of the EU-US Data Privacy Framework or the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), (e) any Digital Services Act (Regulation (EU) 2022/2065) implementing act or Commission guideline that re-scopes the DSA's "hosting service" / "online platform" definitions in a way that brings Balance into scope, (f) any change to the European Electronic Communications Code (Directive (EU) 2018/1972) or to the ePrivacy Directive (Directive 2002/58/EC, as amended by Directive 2009/136/EC) (or the prospective ePrivacy Regulation that replaces it), (g) any change to the Prighter EU representative mandate, or (h) any change to a sub-processor's EU/EEA data-handling posture under our sub-processor register. Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.

This Annex discharges the country-annex obligations referenced in:

This Annex is the canonical EU/EEA-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants an EU/EEA resident a right that the global Policy does not, this Annex governs. Where the global Policy grants an EU/EEA resident a right that this Annex does not, the global Policy governs. The two are read together.


1. Scope and applicability

This Annex applies to every Balance user (parent or kid) whose country of residence is one of the European Union Member States or one of the non-EU European Economic Area Member States listed below.

1.1 EU Member States in scope (27)

Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden.

1.2 Non-EU EEA Member States in scope (3)

Iceland, Liechtenstein, Norway. The EU GDPR was made applicable to the three non-EU EEA Member States by Decision of the EEA Joint Committee No 154/2018 of 6 July 2018, which incorporated Regulation (EU) 2016/679 into Annex XI to the EEA Agreement. The substantive Balance posture is therefore identical for residents of the EU-27 and the EEA-3.

1.3 What is not in scope of this Annex

1.4 How we determine residence

We determine country of residence at install/sign-up time by (a) the country and region the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.

Where the three signals disagree, the most-protective-for-the-data-subject reading is selected, per our internal compliance plan § 6.3.


2. Statutory framework — what applies

The EU/EEA data-protection and online-safety regime sits at the intersection of one Regulation and several Directives + Member State transposing acts. The table below is the canonical Balance-side mapping.

Instrument Short cite What it does Balance's posture
EU General Data Protection Regulation Regulation (EU) 2016/679 ("GDPR") The principal data-protection regime: lawful bases (Art 6), special-category processing (Art 9), children's consent (Art 8), data-subject rights (Arts 12–22), controller / processor obligations (Arts 24–43), international transfers (Chapter V), supervisory authorities (Chapter VI), cooperation and consistency (Chapter VII), remedies and penalties (Chapter VIII). Applies in full to every Member State in § 1.1 and § 1.2. Treatment in §§ 3, 5, 7, 8, 9, 11, 14 below.
Member State national derogations of GDPR Art 8(1) Per § 4 below Each Member State may lower the GDPR default age of digital consent from 16 to any age between 13 and 16. See the per-Member-State table at § 4 below.
ePrivacy Directive Directive 2002/58/EC, as amended by Directive 2009/136/EC and as transposed into each Member State's national law Cookies + similar technologies (Art 5(3)), unsolicited communications (Art 13), location-and-traffic data of users of publicly available electronic-communications services (Arts 6, 9). Applies narrowly to the public legal-documents site (balance.babayagaprogram.com) and to electronic direct marketing. Treatment in § 12 below. Note that an ePrivacy Regulation has been proposed by the European Commission to replace the Directive; if and when it is adopted, this row is re-evaluated.
Digital Services Act Regulation (EU) 2022/2065 ("DSA") Obligations on providers of "intermediary services" (Art 3(g)) — three sub-categories: "mere conduit", "caching", "hosting"; plus enhanced obligations on "online platforms" (Art 3(i)) that store and disseminate user content to the public; further enhanced obligations on "very large online platforms" (VLOPs) and "very large online search engines" (VLOSEs) under Section 5 of Chapter III; specific obligations protecting minors (Arts 14(3), 28, 35(1)(j)). Regulator: the European Commission for VLOPs/VLOSEs; the Member State Digital Services Coordinator ("DSC") for everyone else. Balance is NOT an "intermediary service", a "hosting service", or an "online platform" within the meaning of DSA Art 3 because (i) Balance does not "store information provided by a recipient of the service" within the meaning of Art 3(g)(iii) in a manner that disseminates that information "to the public" within the meaning of Art 3(k); the proof media a kid uploads is end-to-end encrypted and is delivered only to the kid's paired parent device(s) within the same household — it is not stored "at the request of" the kid for dissemination to the public, but is processed under a deterministic parental-control workflow on instruction of the parent who is the data controller as between Balance and the kid for the purposes of the workflow. (ii) Balance has no "online platform" surface within the meaning of Art 3(i): no chat, no public profile, no friends list, no posting, no comments, no DMs, no group rooms, no public gallery, no discovery, no recommendation, no search of users or content, no marketplace. The carve-out is documented in § 5 below.
Audiovisual Media Services Directive Directive 2010/13/EU, as amended by Directive (EU) 2018/1808 ("AVMSD") Obligations on "media service providers" and "video-sharing platform providers". Balance is not a media service provider and not a video-sharing platform provider within the meaning of AVMSD Art 1(1)(aa). The proof-media channel is a household-internal task-completion record, not a video-sharing or media service. Out of scope.
Consumer Rights Directive Directive 2011/83/EU, as amended by Directive (EU) 2019/2161 (the "Omnibus Directive") Pre-contract information (Art 6), 14-day right of withdrawal from distance contracts (Arts 9–14), express-consent rule for the supply of digital content before the withdrawal period expires (Art 16(m)). Applies to the subscription purchase flow. Treatment in Subscription Terms § 20.
Unfair Contract Terms Directive Directive 93/13/EEC Forbids unfair terms in consumer contracts; provides a non-exhaustive list of presumptively unfair terms. Applies to the Terms of Service. Treatment in Terms of Service.
Digital Content and Services Directive Directive (EU) 2019/770 Conformity, remedies, and supply of digital content and digital services to consumers. Applies to the parental-control subscription as a "digital service". Treatment in Subscription Terms.
Unfair Commercial Practices Directive Directive 2005/29/EC, as amended by Directive (EU) 2019/2161 Forbids unfair, misleading, and aggressive commercial practices in business-to-consumer transactions. Applies to every public-facing Balance representation. The truth-check protocol that governs the H1–H8 + M1–M7 + Country Annex bundle is designed to keep every public statement on the inside of this Directive's prohibitions.
Children's Rights — Charter of Fundamental Rights of the European Union Charter Art 24 ("The Rights of the Child"); Charter Art 7 (Respect for private and family life); Charter Art 8 (Protection of personal data) The Charter is the constitutional backstop for every Member State decision applying GDPR to children. Art 24(2) of the Charter requires that in all actions relating to children, whether taken by public authorities or private institutions, the child's best interests must be a primary consideration. The Charter's "best interests" principle is the foundational principle on which the GDPR Art 8 children's regime, the EDPB's children-specific guidelines, and every Member State's age-of-digital-consent derogation rest. Balance's architectural posture is anchored on best interests — see our country classification table § 6.
EDPB Guidelines (selected) EDPB Guidelines 05/2020 on consent (current revision in force); EDPB Guidelines 07/2020 on the concepts of controller and processor; EDPB Guidelines 04/2019 on Article 25 Data Protection by Design and by Default; EDPB Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data; EDPB Guidelines 02/2023 on the technical scope of Art 5(3) ePrivacy Directive; EDPB Guidelines 03/2018 on the territorial scope of the GDPR (Art 3); EDPB Guidelines 02/2024 on Article 6(1)(f) GDPR legitimate interests. EDPB Guidelines are non-binding but are highly persuasive and are followed by every Member State DPA. They form the de facto interpretive layer between the GDPR text and the operational rules below. Balance follows EDPB Guidelines as a matter of policy. The DPIA in our Data Protection Impact Assessment (H8) explicitly engages each of the EDPB Guidelines listed in this row.
European Strategy for a Better Internet for Kids ("BIK+") Commission Communication COM(2022) 212 final The Commission's strategic framework for child-safe online services; not directly binding but referenced by national DPAs and by Member State child-protection authorities. Balance's posture (no advertising; no profiling; no engagement-maximising design; parental-control architecture; end-to-end-encrypted proof media; data-minimised by design) is in conformity with the BIK+ principles.

(The EU AI Act — Regulation (EU) 2024/1689 — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of that Regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the AI Act is deliberate and is not to be read as an implicit statement either way.)


3. EU/EEA supervisory authorities — no one-stop-shop

3.1 No lead supervisory authority

Article 56(1) GDPR creates a "one-stop-shop" mechanism whereby a controller or processor that has a "main establishment" or a "single establishment" in the EU is dealt with by a single lead supervisory authority for cross-border processing. The one-stop-shop is available only to controllers or processors with at least one establishment in the EU.

BabaYaga Program, TOO is established in Kazakhstan and has no establishment within the EU. Accordingly, Article 56 does not apply to Balance, and there is no lead supervisory authority. Each Member State supervisory authority is fully competent under Article 55(1) GDPR for the data of residents of that Member State.

The practical consequence is that an EU/EEA resident may complain to the supervisory authority of the Member State in which the resident habitually resides, in which the resident works, or in which the alleged infringement took place (GDPR Art 77(1)). Each such authority will deal with the complaint on its own competence; the cooperation and consistency mechanisms in Chapter VII GDPR are not engaged because there is no lead supervisory authority to coordinate with.

3.2 Article 27 EU representative as the on-shore intake

To compensate for the absence of an EU establishment, Article 27 GDPR requires us to designate an EU representative when we offer goods or services to EU data subjects. We have designated:

EU Representative: Prighter Group GmbH (trading as Prighter)
Address:           Schellinggasse 3, 1010 Vienna, Austria
Capacity:          GDPR Article 27 representative for the EU/EEA
Mandate:           Balance / BabaYaga Program, TOO — signed by the parties at
                   the start of Phase 2.1 of our internal compliance plan
Public-listing:    privacy.html § 19
Intake:            https://app.prighter.com/portal/12736305032 — EU/EEA data subjects can
                   contact Prighter to file a GDPR enquiry, complaint, or
                   DSAR; Prighter routes the matter to us within one business
                   day.

Designating an Article 27 representative does not transfer controller responsibility from BabaYaga Program, TOO to Prighter — we remain the controller; Prighter is the on-shore point of contact for EU/EEA data subjects and EU/EEA supervisory authorities. An EU/EEA data subject may always contact us directly at ; the Prighter route is provided as an EU/EEA-resident-friendly alternative in the language of the data subject's Member State.

3.3 European Data Protection Board (EDPB)

The EDPB (https://edpb.europa.eu/) is the EU body composed of the heads of one supervisory authority of each Member State and of the European Data Protection Supervisor ("EDPS"). It issues guidelines, recommendations, opinions, and (in defined circumstances under Art 65 GDPR) binding decisions. The EDPB is not a complaint-handling body; complaints go to the relevant Member State DPA per § 4 below.

3.4 European Data Protection Supervisor (EDPS)

The EDPS (https://edps.europa.eu/) is the supervisory authority for the EU institutions, bodies, offices, and agencies. The EDPS is not a competent authority for Balance; an EU/EEA resident does not complain to the EDPS.


The table below is the canonical Balance-side mapping of each EU/EEA Member State to (a) its supervisory authority of competence under GDPR Art 51, (b) the national derogation under GDPR Art 8(1) (age below which a child's consent to information-society services requires verification by the holder of parental responsibility), (c) the in-app legal-locale rendering Balance ships at the Effective date above.

# Member State Supervisory authority Authority URL Age of digital consent (Art 8(1) GDPR) National statute Balance in-app locale
1 Austria Datenschutzbehörde (DSB) https://www.dsb.gv.at/ 14 DSG § 4(4) German (de-AT)
2 Belgium Autorité de protection des données (APD) / Gegevensbeschermingsautoriteit (GBA) https://www.autoriteprotectiondonnees.be/ / https://www.gegevensbeschermingsautoriteit.be/ 13 Loi du 30 juillet 2018, Art 7 French (fr-BE) + Dutch (nl-BE) — both ship
3 Bulgaria Комисия за защита на личните данни (KZLD) https://www.cpdp.bg/ 14 Закон за защита на личните данни, чл. 25а Bulgarian (bg-BG) — Phase 2 locale (not in the 2026-06-09 initial rollout); served in English with a Bulgarian summary card pending
4 Croatia Agencija za zaštitu osobnih podataka (AZOP) https://azop.hr/ 16 Zakon o provedbi Opće uredbe o zaštiti podataka, čl. 19 Croatian (hr-HR) — Phase 2 locale
5 Cyprus Γραφείο Επιτρόπου Προστασίας Δεδομένων Προσωπικού Χαρακτήρα https://www.dataprotection.gov.cy/ 14 Νόμος 125(I)/2018 Greek (el-CY) — Phase 2 locale; served in English
6 Czechia Úřad pro ochranu osobních údajů (ÚOOÚ) https://www.uoou.cz/ 15 Zákon č. 110/2019 Sb., § 7 Czech (cs-CZ) — Phase 2 locale
7 Denmark Datatilsynet https://www.datatilsynet.dk/ 13 Databeskyttelsesloven § 6(3) Danish (da-DK) — Phase 2 locale
8 Estonia Andmekaitse Inspektsioon https://www.aki.ee/ 13 Isikuandmete kaitse seadus § 8 Estonian (et-EE) — Phase 2 locale
9 Finland Tietosuojavaltuutetun toimisto (TSV) https://tietosuoja.fi/ 13 Tietosuojalaki § 5 Finnish (fi-FI) + Swedish (sv-FI) — Phase 2 locales
10 France Commission nationale de l'informatique et des libertés (CNIL) https://www.cnil.fr/ 15 Loi n° 78-17, Art 7-1 French (fr-FR) — initial supported locale (from 2026-06-09)
11 Germany Each of the 16 Land DPAs + Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI) for federal matters Land-specific URLs at https://www.datenschutzkonferenz-online.de/ (DSK portal); BfDI at https://www.bfdi.bund.de/ 16 Bundesdatenschutzgesetz § 1, § 40 + each Land's Datenschutzgesetz German (de-DE) — initial supported locale (from 2026-06-09)
12 Greece Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (HDPA) https://www.dpa.gr/ 15 Ν. 4624/2019, άρθρο 21 Greek (el-GR) — Phase 2 locale
13 Hungary Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) https://www.naih.hu/ 16 Infotv. § 5 (default = 16, no derogation below) Hungarian (hu-HU) — Phase 2 locale
14 Ireland Data Protection Commission (DPC) https://www.dataprotection.ie/ 16 Data Protection Act 2018, s 31 English (en-IE) — initial supported locale (from 2026-06-09)
15 Italy Garante per la protezione dei dati personali https://www.garanteprivacy.it/ 14 D.lgs. 196/2003, art. 2-quinquies Italian (it-IT) — initial supported locale (from 2026-06-09)
16 Latvia Datu valsts inspekcija (DVI) https://www.dvi.gov.lv/ 13 Fizisko personu datu apstrādes likums, 22. pants Latvian (lv-LV) — Phase 2 locale
17 Lithuania Valstybinė duomenų apsaugos inspekcija (VDAI) https://vdai.lrv.lt/ 14 Asmens duomenų teisinės apsaugos įstatymas, 4 str. Lithuanian (lt-LT) — Phase 2 locale
18 Luxembourg Commission nationale pour la protection des données (CNPD) https://cnpd.public.lu/ 16 Loi du 1er août 2018, Art 21 French (fr-LU) + German (de-LU) + Luxembourgish — served in fr-FR / de-DE
19 Malta Information and Data Protection Commissioner (IDPC) https://idpc.org.mt/ 13 Data Protection Act (Cap. 586), Art 4 English (en-MT) — served in en-IE
20 Netherlands Autoriteit Persoonsgegevens (AP) https://www.autoriteitpersoonsgegevens.nl/ 16 Uitvoeringswet AVG, Art 5 (default = 16, no derogation below) Dutch (nl-NL) — initial supported locale (from 2026-06-09)
21 Poland Prezes Urzędu Ochrony Danych Osobowych (UODO) https://uodo.gov.pl/ 16 Ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych, Art 6 (default = 16, no derogation below) Polish (pl-PL) — Phase 2 locale
22 Portugal Comissão Nacional de Proteção de Dados (CNPD) https://www.cnpd.pt/ 13 Lei n.º 58/2019, Art 16 Portuguese (pt-PT) — Phase 2 locale
23 Romania Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) https://www.dataprotection.ro/ 16 Legea 190/2018, Art 1 (default = 16, no derogation below) Romanian (ro-RO) — Phase 2 locale
24 Slovakia Úrad na ochranu osobných údajov Slovenskej republiky https://dataprotection.gov.sk/ 16 Zákon č. 18/2018 Z. z., § 15 (default = 16, no derogation below) Slovak (sk-SK) — Phase 2 locale
25 Slovenia Informacijski pooblaščenec (IP) https://www.ip-rs.si/ 15 Zakon o varstvu osebnih podatkov ZVOP-2, čl. 14 Slovenian (sl-SI) — Phase 2 locale
26 Spain Agencia Española de Protección de Datos (AEPD) https://www.aepd.es/ 14 Ley Orgánica 3/2018, Art 7 Spanish (es-ES) — initial supported locale (from 2026-06-09)
27 Sweden Integritetsskyddsmyndigheten (IMY) https://www.imy.se/ 13 Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning, 2 kap. 4 § Swedish (sv-SE) — Phase 2 locale
28 Iceland (EEA) Persónuvernd https://www.personuvernd.is/ 13 Lög um persónuvernd nr. 90/2018, 8. gr. Icelandic (is-IS) — Phase 2 locale; served in en-IE
29 Liechtenstein (EEA) Datenschutzstelle (DSS) https://www.datenschutzstelle.li/ 16 Datenschutzgesetz (DSG) Art 5 (default = 16, no derogation below) German (de-LI) — served in de-DE
30 Norway (EEA) Datatilsynet (NO) https://www.datatilsynet.no/ 13 Personopplysningsloven § 5 Norwegian (nb-NO + nn-NO) — Phase 2 locale; served in en-IE

Balance is a parental-control service in which the parent — i.e., the holder of parental responsibility under the applicable Member State family-law framework — sets up the account, configures the kid profile, and pairs the kid's device. Verifiable Parental Consent is obtained from the parent at kid onboarding (cross-reference: Children's Privacy Notice § 5; United States annex § 5) regardless of the kid's age. The Member-State variance in the Article 8(1) age threshold therefore does not unlock a kid-self-serve consent path inside Balance — the parent always consents on the kid's behalf.

The variance nonetheless drives two operational consequences:


5. Digital Services Act (DSA) — applicability analysis

The DSA (Regulation (EU) 2022/2065) creates a layered set of obligations on three classes of providers:

5.1 Why Balance is not a hosting service under Art 3(g)(iii)

Article 3(g)(iii) defines a "hosting" service as one that "consists of the storage of information provided by, and at the request of, a recipient of the service".

Balance's proof-media architecture does not satisfy that definition. The proof file is:

The kid is not "requesting storage" in the autonomous Art 3(g)(iii) sense — the kid is completing a parent-assigned task within a deterministic parental-control workflow, and the parent (as the holder of parental responsibility and the data controller under whose instruction the workflow runs) is the recipient and the requestor. There is no third-party recipient. There is no public dissemination. The cipher payload is opaque to Balance, opaque to Google Cloud Storage, and opaque to every Balance sub-processor.

Even on the alternative reading that proof media is "stored" within Art 3(g)(iii), the further condition in Art 3(i) — that the information be "disseminated to the public" — is not satisfied. Art 3(k) defines "dissemination to the public" as "making information available, at the request of the recipient of the service that provided the information, to a potentially unlimited number of third parties". Balance disseminates nothing to "an unlimited number of third parties"; the proof is end-to-end-encrypted to the paired parent device(s) of the same household and to no other recipient.

5.2 Why Balance is not an online platform under Art 3(i)

Independently of § 5.1, Balance has no "online platform" surface within the meaning of Art 3(i). Specifically:

Cross-references: the Play Console Data Safety form § 2 (Contains ads: No; Shared with third parties: No on every row); the Play Console Child Safety Standards declaration § 3 ATTESTATION-A (no multi-user surface), ATTESTATION-D (no advertising), ATTESTATION-G (no third-party sharing); the Play Console Target Audience form § 3 M7-A5 (no multi-user surface in app).

5.3 Why Balance is not a VLOP/VLOSE

VLOP and VLOSE designation under DSA Art 33 requires an average of 45 million monthly active recipients in the Union and a formal Commission designation decision. Balance's current user base is materially below that threshold. If Balance ever crosses the threshold and is formally designated, the Section 5 of Chapter III enhanced obligations attach and this row is re-evaluated in an off-cycle review.

5.4 DSA child-protection obligations — voluntary best-effort honor

DSA Art 14(3) requires that providers of intermediary services likely to be accessed by minors include in their terms and conditions a clear and unambiguous explanation of any restrictions imposed in respect of the use of the service. DSA Art 28 requires that providers of online platforms accessible to minors put in place "appropriate and proportionate measures to ensure a high level of privacy, safety, and security of minors, on their service". DSA Art 35(1)(j) requires VLOPs/VLOSEs to assess and mitigate systemic risks to the protection of minors as part of their annual risk assessment.

Even though Balance is not in scope as an intermediary service, an online platform, or a VLOP/VLOSE (per § 5.1–§ 5.3), Balance voluntarily honors the substance of these provisions:

5.5 If Balance ever introduces an in-scope surface

If Balance were ever to introduce a surface that brings it into scope as a hosting service or an online platform — for instance, a kid-to-kid or family-to-family social surface, a public profile, a discovery feed, or a marketplace — the DSA obligations would attach and a full DSC-track compliance programme would be required (notice-and-action, internal complaint-handling, transparency reporting, trusted-flagger cooperation, designation of a single point of contact, statement-of-reasons obligations). This Annex would be re-validated immediately and republished. The annual-review item in § 19 below explicitly checks for any introduction of an in-scope surface.


6. GDPR rights — the rights, the timeline, and how to exercise them

6.1 The rights catalogue

An EU/EEA resident has the following rights under the GDPR.

6.2 Timeline

6.3 Identity verification

Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity (Art 12(6)). The identity-verification protocol uses the parent's existing authentication credential (email + password + the device-mismatch token defence — cross-reference: our internal data-flow map § 2.1, § 2.17). Out-of-band identity verification (e.g., a copy of a government-issued identity document) is requested only as a last resort and only for the parent, and only for the categories of personal information that require a higher assurance of identity.

6.4 No cost

The exercise of any GDPR right is free of charge (Art 12(5)).

6.5 Language

A request may be submitted in any of the initial supported locales in § 4 above (English, Spanish, French, German, Italian, Dutch); requests in other EU/EEA languages are accepted and Balance will use a professional translation provider on a best-effort basis to respond in the language of the request. Cross-reference: Privacy Policy § 16.


7. Children's data — GDPR Article 8 + Member State derogations

GDPR Article 8(1) sets the default age of digital consent at 16, subject to a Member State derogation that may lower it to any age between 13 and 16. The per-Member-State derogations are tabulated in § 4 above.

Balance does not rely on a kid-self-serve Article 8 consent path. Verifiable Parental Consent is obtained from the parent at kid onboarding, in every Member State, regardless of the kid's age. The Article 8(1) derogation is therefore informational only — it informs the parent of the legislator's preferred threshold and frames the wording of the Children's Privacy Notice (H2 § 14) in each Member State's locale.

GDPR Article 8(2) requires the controller to make reasonable efforts to verify in such cases that consent is given or authorised by the holder of parental responsibility over the child, taking into consideration available technology. Balance's parent-account-creation + payment-method capture + in-app kid-pairing flow is the verifiable-parental-consent mechanism for this purpose; the mechanism is identical to the VPC mechanism described in United States annex § 5 and is documented in our internal data-flow map § 2.7.

GDPR Article 6(1)(f) — the legitimate-interests lawful basis — is engaged only for the narrow operational categories enumerated in our Data Protection Impact Assessment § 7 (LIA), and never as the lawful basis for processing a kid's personal data; the kid-side processing is anchored on Article 6(1)(a) parental consent and on Article 6(1)(b) performance of the contract that the parent entered into with Balance.


8. International data transfers from the EU/EEA

The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every EU/EEA resident's data leaves the EU/EEA at the point of being uploaded to the Balance backend.

8.1 Transfer mechanism — the EU-US axis (Emergent + Google + Resend)

GDPR Chapter V governs international transfers. Balance relies on the following stack to satisfy Chapter V for the EU-US axis:

8.2 Transfer mechanism — the EU-KZ axis (controller administrative access)

The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes (incident response, account-deletion verification, support escalations). Because Kazakhstan is a third country and Kazakhstan is not the subject of an EU adequacy decision, the controller-leg of the data flow is covered by EU SCCs Module 4 (processor-to-controller) in the inverse, treating Emergent Labs as the data exporter and BabaYaga Program, TOO as the data importer in respect of the operational access. The Kazakhstan personal-data-protection regime (Закон Республики Казахстан "О персональных данных и их защите" № 94-V от 21 мая 2013 года, as amended) is the substantive overlay; the TIA for the KZ leg is in our international-transfer pack § 7.

8.3 No Schrems II essential-equivalence challenge for proof media

The proof-media payload — the kid's photo / video / audio proof that a task was completed — never reaches the Balance backend or any sub-processor in plaintext. The architecture is documented in our encryption-posture record § 2: the proof file is encrypted on the kid's device with a fresh per-file file-encryption key (XChaCha20-Poly1305) wrapped to each authorised parent device's X25519 public key, before any network call; the ciphertext is uploaded directly to Google Cloud Storage via a 5-minute V4 signed URL minted by the backend; the backend itself does not see plaintext bytes at any point.

Accordingly, the Schrems II essential-equivalence challenge has no purchase on proof media as a category of EU/EEA resident personal data being transferred to the US: there is no plaintext to be intercepted, no plaintext to be compelled under 50 U.S.C. § 1881a (s 702 FISA), no plaintext to be subject to Executive Order 12333, no plaintext to be subject to a National Security Letter, no plaintext to be subject to the U.S. CLOUD Act. The supplementary measure is fully effective.

For the residual categories of data that are transferred in plaintext (the parent's email; the kid's display name; the deterministic per-kid usage-log aggregates; the parent's authentication tokens), the DPF + SCCs + the TIA + the technical-and-organisational measures table in our Records of Processing Activities (Article 30) § 7 together satisfy GDPR Chapter V.

8.4 Article 49 derogations — not relied upon

We do not rely on the Article 49 derogations (consent, contract necessity, important reasons of public interest, etc.) as the basis for our routine EU-US data flows. Article 49 derogations are reserved for non-routine, ad-hoc transfers; Balance's flows are routine, structural, and require a Chapter V transfer tool.


9. Data residency for EU/EEA residents

Question Answer
Where is the backend hosted? United States. Emergent Labs Inc. (Delaware) on US infrastructure.
Where is the MongoDB database located? United States.
Where is the proof-media storage located? United States — Google Cloud Storage us multi-region.
Where are push notifications dispatched from? United States — Firebase Cloud Messaging.
Is any EU/EEA resident's data held in the EU/EEA? No. Every EU/EEA resident's data is held in the United States. The GDPR Chapter V transfer mechanism in § 8 above is the legal basis for the transfer.
Where is the controller? Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor DPAs and via the EU SCCs Module 4 inverse arrangement in § 8.2.
Where is the EU representative? European Union — Prighter Group GmbH at Schellinggasse 3, 1010 Vienna, Austria.

The decision to centralise on a US-only backend (rather than to split storage by region) is documented in our internal compliance plan § 6 (data residency policy). The transfer pack (our international-transfer pack) is the substantive instrument that makes the policy lawful under GDPR Chapter V; the end-to-end encryption of proof media is the principal supplementary measure that makes the Schrems II-style essential-equivalence challenge defensible for proof media.


10. Sub-processors touching EU/EEA resident data

Sub-processor Role Location of processing EU/EEA transfer paperwork
Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer Hosts the FastAPI backend + MongoDB cluster United States EU-US DPF self-certification status verified annually per our international-transfer pack § 3.1; EU SCCs Module 2 on file as a fallback / parallel transfer tool; E2EE supplementary measure for proof media.
Google LLC — Google Cloud Storage (USA) Stores end-to-end-encrypted proof-media ciphertext United States (us multi-region) Google's EU-US DPF self-certification + Google's EU SCCs (under the Cloud Data Processing Addendum); ciphertext-only handling.
Google LLC via Google Cloud (USA) Periodic (daily) backups of our operational database United States (us multi-region) Google's EU-US DPF self-certification + Google's EU SCCs (under the Cloud Data Processing Addendum); the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted.
Google LLC — Firebase Cloud Messaging Delivers push notifications to EU/EEA kid + parent devices United States DPF + SCCs as above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures).
Google LLC — Google Sign-In Authenticates parent Google identity (when used) United States DPF + SCCs as above.
Google LLC — Google Play Billing Processes subscription purchases United States DPF + SCCs as above; Google Play Developer Distribution Agreement.
Resend, Inc. (San Francisco, CA, USA) Delivers transactional email to EU/EEA parent users United States DPF self-certification check + EU SCCs Module 2 on file.
Prighter Group GmbH (Austria, EU) EU Article 27 representative European Union (Austria) Not a transfer — Prighter is the on-shore EU representative.

Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7. The full sub-processor list, with each row's DPA status and DPF self-certification verification date, is at our sub-processor register.


11. Article 30 record of processing activities

GDPR Article 30 requires the controller to maintain a record of processing activities. The Balance Article 30 record is at our Records of Processing Activities (Article 30) (H7, classified Internal). It enumerates each Processing Activity (PA-*) row with the categories of data subjects, categories of personal data, purposes of processing, lawful basis, retention period, recipients, transfers, and technical-and-organisational measures.

An EU/EEA supervisory authority is entitled to request a copy of the Article 30 record upon request (Art 30(4)); we will provide a copy promptly upon receipt of a valid request, routed through Prighter as our EU representative.


12. ePrivacy Directive — cookies and electronic direct marketing

The ePrivacy Directive (Directive 2002/58/EC, as amended by Directive 2009/136/EC) governs the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user (Art 5(3)) and electronic direct marketing (Art 13). The Directive is implemented through each Member State's national law.

12.1 In-app — strictly-necessary storage only

The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is exempt from the Art 5(3) consent requirement under the strictly-necessary carve-out (Recital 66 of Directive 2009/136/EC + EDPB Guidelines 02/2023 on the technical scope of Art 5(3)).

The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins that set third-party state. A short Art 5(3) notice is published in the site footer. The site is therefore a one-click no-consent-banner-required site, on the EDPB Guidelines 02/2023 reading.

12.3 Electronic direct marketing — not sent

Balance does not send electronic direct marketing. The only email Balance sends to EU/EEA parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications (e.g., "your kid completed a task"). Transactional email is outside the Article 13 "marketing" definition. If we ever introduce a marketing channel, we will obtain opt-in consent (Art 13(1)) and provide an unsubscribe in every message; we will also satisfy each Member State's specific transposition (e.g., France's CNIL guidelines; Germany's UWG § 7).


13. Breach notification — GDPR Article 33/34

Audience Trigger Deadline Channel
Competent supervisory authority of each Member State A personal-data breach within GDPR Art 4(12), unless unlikely to result in a risk to the rights and freedoms of natural persons. 72 hours after becoming aware (Art 33(1)). The competent Member State authority is determined by reference to where affected data subjects habitually reside; each authority's online breach-notification form (e.g., CNIL, BfDI / Land DPA, Garante, AEPD, AP, DPC, etc.) is the channel. Because there is no one-stop-shop (§ 3.1 above), each competent authority is notified separately. Prighter as our EU representative coordinates the multi-jurisdiction notification under the runbook in our breach-notification runbook § 9.1.
Affected data subjects A breach likely to result in a high risk to the rights and freedoms of natural persons. Without undue delay (Art 34(1)). Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable.
CSAE-specific An incident with a CSAE component. Per the routes in § 15 below + the internal runbook (M1). National INHOPE member + national child-protection authority + (where applicable) Member State law enforcement.

The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9.1: preliminary classification within one business day, fuller assessment within seven days, supervisory-authority notification within the statutory 72-hour window, affected-data-subject notification per the Art 34 trigger.


14. Complaint routes (summary)

An EU/EEA resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities. The first-line route is the resident's own Member State DPA (per § 4 above); the other routes are available as alternative or supplementary fora.

Authority Subject matter Address / URL
Member State DPA of the resident's habitual residence GDPR + Member State data-protection law + ePrivacy national transposition See § 4 table above.
Member State DPA of the place where the alleged infringement took place GDPR (Art 77(1) alternative forum) See § 4 table above.
Member State DPA of the resident's place of work GDPR (Art 77(1) alternative forum) See § 4 table above.
Member State Digital Services Coordinator ("DSC") DSA — even though Balance is not in scope (§ 5), the DSC is the right addressee for any systemic DSA concern. Each Member State publishes its DSC at the European Commission's DSC list at https://digital-strategy.ec.europa.eu/en/policies/digital-services-coordinators.
European Data Protection Board (EDPB) Strategic / cross-Member-State coordination https://edpb.europa.eu/our-work-tools/our-documents/our-documents_en (publications); EDPB does not handle individual complaints.
Member State consumer-protection authority Consumer Rights Directive 2011/83/EU + Unfair Contract Terms Directive 93/13/EEC + Digital Content and Services Directive (EU) 2019/770 E.g., DGCCRF (France); Bundeskartellamt + the Verbraucherzentrale network (Germany); ACM (Netherlands); ENERGY-and-Consumer Affairs Ministry equivalents in each Member State.
European Consumer Centres Network (ECC-Net) Cross-border consumer issues https://commission.europa.eu/live-work-travel-eu/consumer-rights-and-complaints/resolve-your-consumer-complaint/european-consumer-centres-network-ecc-net_en

An EU/EEA resident may always first raise the matter with us at (DSAR; named individual: ) or via the Prighter EU intake at https://app.prighter.com/portal/12736305032. We will respond within the GDPR Art 12(3) timeline in § 6.2 above. Raising the matter with us first is not a precondition to complaining to a supervisory authority; every Member State DPA accepts complaints directly (Art 77(1) GDPR).


15. CSAE reporting routes — EU/EEA

An EU/EEA resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:

The full CSAE Country Routing Table is in Child Safety Standards § 8.6.


16. Consumer rights — the EU consumer-acquis overlay

Where the parent is acting as a "consumer" within the meaning of Directive 2011/83/EU Art 2(1) — i.e., any natural person acting for purposes which are outside the parent's trade, business, craft or profession — the following consumer-acquis overlays apply to the subscription purchase flow and to the Terms of Service.

16.1 Pre-contract information and 14-day right of withdrawal

Directive 2011/83/EU Art 6 requires that the parent be given mandatory pre-contract information before the conclusion of a distance contract. Directive 2011/83/EU Arts 9–14 grant the parent a 14-day right of withdrawal from the contract, computed from the day the contract is concluded for a service contract, or from the day the parent acquires physical possession of the goods for a goods contract.

Balance's subscription is a digital service. Where the parent expressly consents at subscription time to immediate performance of the contract, and acknowledges that consent results in the loss of the right of withdrawal once the contract is fully performed (Art 16(m) of the Consumer Rights Directive), the right of withdrawal is forgone for the period after immediate performance commences. The express-consent + acknowledgement step is implemented at the subscription purchase screen and is documented in Subscription Terms § 20.

16.2 Unfair contract terms

Directive 93/13/EEC requires that contract terms which have not been individually negotiated are not binding on the consumer where they cause, contrary to the requirement of good faith, a significant imbalance in the parties' rights and obligations to the detriment of the consumer. The non-exhaustive list in the Annex to the Directive is observed in the drafting of Terms of Service.

16.3 Digital content and services — Directive (EU) 2019/770

Directive (EU) 2019/770 requires that digital content and digital services supplied to consumers be supplied in conformity with the contract, that the supplier remedy any lack of conformity, and that the supplier provide updates necessary to maintain conformity for the period reasonably expected. Treatment in Subscription Terms.

16.4 Unfair Commercial Practices Directive

Directive 2005/29/EC forbids unfair commercial practices in business-to-consumer transactions. Each public statement by Balance is verified against the truth-check protocol described in our internal compliance tracker and in the editorial protocol that governs every new draft. No misleading commercial practice is conducted by Balance.


17. Cross-references


18. Versioning and review

This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:


End of European Union and European Economic Area Country Annex.

← Back to Privacy Policy · Children's Privacy Notice