← All legal documents · Privacy Policy · Children's Privacy Notice

Balance — European Microstates Bundle Country Annex (Andorra · Monaco · San Marino)

Effective date: 28 June 2026 Last updated: 28 June 2026

Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every resident of the Principality of Andorra (Catalan: Principat d'Andorra; ISO 3166-1 alpha-2 "AD"), the Principality of Monaco (French: Principauté de Monaco; ISO 3166-1 alpha-2 "MC"), and the Most Serene Republic of San Marino (Italian: Serenissima Repubblica di San Marino; ISO 3166-1 alpha-2 "SM") — referred to collectively in this Annex as the "Microstates" — covered by this Annex; the Data Protection Officer ("DPO") for the purposes of the Andorran Llei 29/2021, del 28 d'octubre, qualificada de protecció de dades personals ("APDA Act 2021") read with its enforcement regulations, the Monégasque Loi n° 1.165 du 23 décembre 1993 relative à la protection des informations nominatives as substantively amended by Loi n° 1.565 du 3 décembre 2024 (the "Monaco Personal Data Protection Reform Act 2024") with most substantive provisions in force from 3 July 2025, and the Sammarinese Legge 21 dicembre 2018 n. 171 — Protezione delle persone fisiche con riguardo al trattamento dei dati personali as amended by Decreto Delegato 16 maggio 2019 n. 64 and most recently amended by Legge 27 maggio 2025 n. 60Balance is engaged on the most-protective reading of all three Microstate regimes for the parental-control service which processes children's personal data as a core activity, with business contact published as the publicly-accessible DPO contact required by each Microstate's statutory framework + Council of Europe Convention 108+ Article 10 (entrusted-person publicly-available contact requirement applicable in each Microstate as a Convention-108+ contracting party); the designated contact point for the Andorran Data Protection Agency (Catalan: Agència Andorrana de Protecció de Dades, the "APDA"), the Monégasque Commission de Contrôle des Informations Nominatives ("CCIN"), the Sammarinese Autorità Garante per la Protezione dei Dati Personali (the "Garante San Marino"), each Microstate's Ministry of Justice + Ministry of Internal Affairs / Police, and (under the Council of Europe + EU monetary-area framework) the European Data Protection Board (the "EDPB") + the Council of Europe Convention 108+ Consultative Committee (Chinese: n/a — Council of Europe French and English working languages) under their respective intake protocols. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to the Andorran Llei 29/2021, del 28 d'octubre, qualificada de protecció de dades personals ("APDA Act 2021") (published Butlletí Oficial del Principat d'Andorra (BOPA) n° 124 of 17 November 2021; in force from 17 May 2022; the GDPR-aligned modernisation that replaced the prior Llei 15/2003, del 18 de desembre, qualificada de protecció de dades personals and the Reglament d'aplicació de la Llei 15/2003); the APDA Act 2021 Enforcement Regulations as issued by the Andorran Govern under Article 99 of the APDA Act 2021; (b) any amendment to the Monégasque Loi n° 1.165 du 23 décembre 1993 relative à la protection des informations nominatives as substantively reformed by Loi n° 1.565 du 3 décembre 2024 portant réforme de la loi n° 1.165 du 23 décembre 1993 relative à la protection des informations nominatives (the "Monaco Personal Data Protection Reform Act 2024" / the "Monaco 2024 Reform Act"), published Journal de Monaco — Bulletin Officiel de la Principauté n° 8722 of 13 December 2024 with most substantive provisions in force from 3 July 2025 (the seven-month vacatio legis); the Monaco Implementing Sovereign Ordinances (Monégasque: Ordonnances Souveraines) issued under the Monaco 2024 Reform Act including the Ordonnance Souveraine n° 10.638 du 24 mars 2025 portant application de la loi n° 1.165; (c) any amendment to the Sammarinese Legge 21 dicembre 2018 n. 171 — Protezione delle persone fisiche con riguardo al trattamento dei dati personali e relativa libera circolazione ("Legge n. 171/2018"); as substantively amended by Decreto Delegato 16 maggio 2019 n. 64 (the "Sammarinese Implementing Decree 2019") and most recently amended by Legge 27 maggio 2025 n. 60 — Modifiche alla Legge n. 171/2018 (the "Sammarinese 2025 Amendment Act"); the Sammarinese Garante Decisions and Subordinate Regulations issued at https://www.garanteprivacy.sm/; (d) any amendment to the body of Council of Europe instruments to which each Microstate is a contracting party — in particular Convention 108 — Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data of 28 January 1981 (ETS No. 108) (Andorra acceded 1 February 2008 in force 1 June 2008; Monaco acceded 28 September 2009 in force 1 January 2010; San Marino acceded 16 November 2005 in force 1 March 2006); Convention 108+ — Protocol amending the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data of 10 October 2018 (CETS No. 223) (Andorra signed 10 October 2018 + ratified 8 February 2022; Monaco signed 10 October 2018 + ratification status monitored under § 18; San Marino signed 10 October 2018 + ratified 25 November 2019 in force 1 April 2020 — among the earliest contracting parties to bring Convention 108+ into force, second after Bulgaria); Convention on Cybercrime of 23 November 2001 (ETS No. 185, the "Budapest Convention") (Andorra signed 23 November 2001 + ratified 16 November 2014 + in force for Andorra from 1 March 2015; Monaco signed 2 May 2013 + ratified 17 March 2017 + in force for Monaco from 1 July 2017; San Marino signed 17 March 2017 + ratified 21 May 2019 + in force for San Marino from 1 September 2019); Second Additional Protocol to the Convention on Cybercrime on enhanced co-operation and disclosure of electronic evidence (CETS No. 224, opened for signature 12 May 2022) (Andorra signed 12 May 2022 + ratification status monitored under § 18; Monaco + San Marino signing/ratification status monitored under § 18); Convention 201 — Council of Europe Convention on the Protection of Children against Sexual Exploitation and Sexual Abuse of 25 October 2007 (CETS No. 201, the "Lanzarote Convention") — Andorra ratified 19 February 2014 in force 1 June 2014; Monaco ratified 24 September 2014 in force 1 January 2015; San Marino ratified 22 March 2010 in force 1 July 2010; (e) any amendment to the body of EU instruments which apply to each Microstate by virtue of the EU-Andorra Monetary Agreement of 30 June 2011 (Andorra in the Eurozone via Monetary Agreement; Council Decision 2011/415/EU) read with the Andorra Customs Union Agreement of 1990, the EU-Monaco Monetary Agreement of 29 November 2011 (Monaco in the Eurozone via Monetary Agreement; Council Decision 2011/657/EU), and the EU-San Marino Monetary Agreement of 27 March 2012 (San Marino in the Eurozone via Monetary Agreement; Council Decision 2012/189/EU) — insofar as the Monetary Agreements oblige the Microstates to align with certain EU instruments (principally financial-services and AML/CTF instruments; the EU Monetary Agreements do NOT directly oblige alignment with the GDPR but each Microstate has nonetheless aligned its data-protection framework with the GDPR by independent domestic legislative choice); (f) any decision of (i) for Andorra: the Tribunal de Batlles, Tribunal de Corts, Tribunal Superior de Justícia d'Andorra, Tribunal Constitucional d'Andorra under the Constitution of 28 April 1993; (ii) for Monaco: the Tribunal de Première Instance, Tribunal Criminel, Cour d'Appel, Cour de Révision (the highest civil and criminal court of Monaco), Tribunal Suprême de Monaco (the constitutional court) under the Constitution of 17 December 1962 as revised 2002; (iii) for San Marino: the Tribunale Unico della Repubblica di San Marino (the unitary court system), the Giudice di Appello, the Collegio Garante della Costituzionalità delle Norme (the constitutional review body) under the Dichiarazione dei Diritti dei Cittadini (Declaration of Citizens' Rights) of 8 July 1974 read with the Statuti (Statutes) of 1600 still in force as the constitutional anchor; bearing on each Microstate's data-protection framework; (g) any amendment to each Microstate's Criminal Code — for Andorra the Codi Penal del Principat d'Andorra (Llei 9/2005 del 21 de febrer); for Monaco the Code pénal de Monaco (in particular Article 294-3 child pornography production/distribution + Article 294-5 child pornography possession + Article 235 sexual offences against minors + the body of Loi n° 1.382 of 20 July 2011 strengthening the fight against certain criminal offences); for San Marino the Codice Penale della Repubblica di San Marino (Legge 25 febbraio 1974 n. 17 as substantively amended); (h) any amendment to each Microstate's children-protection statute — for Andorra Llei 14/2019, del 15 de febrer, qualificada dels drets dels infants i adolescents (the principal Andorran child-rights statute, the "Andorra Children Rights Act 2019"); for Monaco Loi n° 1.382 du 20 juillet 2011 sur la prévention et la répression des violences particulières + Loi n° 1.344 du 26 décembre 2007 (child welfare); for San Marino Legge 20 luglio 1990 n. 83 — Legge quadro sulla protezione dei minori + Legge 26 febbraio 2004 n. 17 — Norme in tema di tutela dei minori; (i) any amendment to each Microstate's electronic communications and cybercrime statute — for Andorra Llei 26/2014, del 30 d'octubre, sobre el règim jurídic dels delictes informàtics + the Budapest Convention domestication; for Monaco Loi n° 1.299 du 15 juillet 2005 sur la liberté d'expression publique + Loi n° 1.520 du 11 février 2022 relative à la cybersécurité; for San Marino the Budapest-Convention domestic-implementation framework in Codice Penale + Codice di Procedura Penale; (j) any amendment to each Microstate's consumer-protection statute — for Andorra Llei 13/2013, del 13 de juny, de competència efectiva i protecció del consumidor; for Monaco Loi n° 1.383 du 2 août 2011 sur l'économie numérique + Code de Commerce + Code Civil; for San Marino Legge 29 luglio 2013 n. 92 — Legge sulla disciplina del commercio elettronico; (k) any amendment to each Microstate's electronic transactions and electronic signature framework; (l) any amendment to a sub-processor's posture vis-à-vis any Microstate under our sub-processor register; (m) the bringing into force of any post-Effective-date Microstate regulation governing automated processing or related techniques (covered by the deliberate-silence carve-out in § 2 of this Annex); (n) any change to each Microstate's EU adequacy status — Andorra holds Commission Decision 2010/625/EU of 19 October 2010 (the "Andorra Adequacy Decision 2010") (first periodic review under GDPR Article 45(4) confirmed January 2024); Monaco does NOT hold EU adequacy at the Effective date (adequacy assessment is pending — § 18 versioning trigger); San Marino does NOT hold formal EU adequacy at the Effective date (the Memorandum of Understanding between the Republic of Italy and the Republic of San Marino on Personal Data Protection of 2017 + the integration of EU instruments via the EU Monetary Agreement framework facilitate Italy↔San Marino + EU↔San Marino flows but no formal Commission Article 45 decision has been issued — § 18 versioning trigger); (o) any Decision, Recommendation, Guideline, or Resolution issued by the EDPB or the Council of Europe Convention 108+ Consultative Committee bearing on each Microstate's framework. Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3. This bundle is drafted per the approved Option B microstates-bundling strategy documented in our internal compliance tracker (Andorra + Monaco + San Marino bundled in one file given their (i) microstate scale, (ii) shared Council-of-Europe Convention 108/108+ + Budapest Convention + Lanzarote Convention layered framework, and (iii) Eurozone-via-Monetary-Agreement status without EU membership).

This Annex discharges the country-annex obligations referenced in:

This Annex is the canonical Microstates-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a Microstate resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a Microstate resident a right that this Annex does not, the global Policy governs. The two are read together.

This Annex is drafted in English. The official languages of the Microstates are: - Andorra: Catalan (Catalan: català) under Constitution of 28 April 1993 Article 2 paragraph 1 ("La llengua oficial de l'Estat és el català"); Spanish + French + Portuguese widely used. - Monaco: French (French: français) under Constitution of 17 December 1962 Article 8 ("La langue française est la langue officielle de l'État"); Monégasque (the historical Romance language of Monaco) + Italian + English widely used. - San Marino: Italian (Italian: italiano) — by long-standing constitutional custom + the Statuti of 1600 + the Dichiarazione dei Diritti dei Cittadini of 8 July 1974.

Catalan + French + Italian translations of this Annex are queued for the Phase-2 locale rollout per our internal compliance tracker. No translation is statutorily required at the Effective date for the English-language privacy notice to a Microstate resident (each Microstate's regulator interpretive practice accepts notices in English provided the notice is intelligible to the data subject — the APDA, CCIN, and Garante San Marino transitional + interpretive practice prefer the respective official language for materially-affected resident data subjects, which Balance will deliver via the Phase-2 locale rollout).


1. Scope and applicability

This Annex applies to every Balance user (parent or kid) whose country of residence is any of the three Microstates:

1.1 Andorra (AD)

The Principality of Andorra — co-principality state in the eastern Pyrenees between France and Spain; population approximately 79,000; the Co-Princes are the President of the French Republic and the Bishop of Urgell (Spain) per the Constitution of 28 April 1993 Article 43 paragraph 2; organised into 7 parishes (Catalan: parròquies) — Andorra la Vella, Canillo, Encamp, Escaldes-Engordany, La Massana, Ordino, and Sant Julià de Lòria; Eurozone via the EU-Andorra Monetary Agreement of 30 June 2011 (Council Decision 2011/415/EU); Council of Europe member since 10 November 1994; UN member since 28 July 1993. There is no provincial-level data-protection sub-layer that derogates from the APDA Act 2021 in respect of Balance's commercial processing.

1.2 Monaco (MC)

The Principality of Monaco — sovereign city-state on the French Riviera; population approximately 39,000; ruled by the Sovereign Prince of Monaco under the Constitution of 17 December 1962 as substantively revised by Loi n° 1.249 du 2 avril 2002 (the "2002 Constitutional Revision"); organised into 10 wards (French: quartiers) — Monaco-Ville (the historic centre on the Rocher), La Condamine, Monte-Carlo, Fontvieille, Moneghetti, La Rousse, Saint-Roman, Larvotto, La Colle, and Les Révoires; Eurozone via the EU-Monaco Monetary Agreement of 29 November 2011 (Council Decision 2011/657/EU); Council of Europe member since 5 October 2004; UN member since 28 May 1993. There is no provincial-level data-protection sub-layer that derogates from the Loi n° 1.165/1993 as reformed by the Monaco 2024 Reform Act in respect of Balance's commercial processing.

1.3 San Marino (SM)

The Most Serene Republic of San Marino — the world's oldest continuously functioning republic (traditionally founded 301 AD); sovereign enclave entirely surrounded by Italy in the Emilia-Romagna + Marche regions; population approximately 34,000; constitutionally anchored on the Statuti della Repubblica di San Marino of 1600 (the oldest still-in-force written constitution in the world) supplemented by the Dichiarazione dei Diritti dei Cittadini e dei Principi Fondamentali dell'Ordinamento Sammarinese (Declaration of Citizens' Rights) Legge n. 59 of 8 July 1974 as substantively amended (most recently by Legge Costituzionale n. 1 del 19 settembre 2019); organised into 9 castelli (municipalities) — Acquaviva, Borgo Maggiore, Chiesanuova, Domagnano, Faetano, Fiorentino, Montegiardino, Città di San Marino (capital), and Serravalle; Eurozone via the EU-San Marino Monetary Agreement of 27 March 2012 (Council Decision 2012/189/EU); Council of Europe member since 16 November 1988; UN member since 2 March 1992. There is no municipal-level data-protection sub-layer that derogates from Legge n. 171/2018 as amended by the Sammarinese 2025 Amendment Act in respect of Balance's commercial processing.

1.4 Residence determination

We determine country of residence at install/sign-up time by (a) the country the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.

Where any of the three signals identifies any of the three Microstates as the country of residence, the applicable portion of this Annex (and the consolidated parts) applies, even if the other signals are non-Microstate. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.

1.5 Extraterritorial reach


2. Statutory framework — what applies

The three Microstates share a common Council-of-Europe foundational layer (Convention 108 + Convention 108+ + Budapest Convention + Lanzarote Convention) and have each independently aligned their domestic data-protection framework with the GDPR substantive standards (Andorra most directly via the APDA Act 2021; Monaco via the Monaco 2024 Reform Act in force 3 July 2025; San Marino via Legge n. 171/2018 + the Sammarinese 2025 Amendment Act).

Instrument Short cite What it does Balance's posture
Constitution of the Principality of Andorra of 28 April 1993 Constitution of Andorra — the principal Andorran constitutional document, adopted by referendum 14 March 1993 + ratified by the Co-Princes 28 April 1993 + in force from 4 May 1993 (the first written constitution of Andorra — until then governed by the Pareatges of 1278). Article 2 paragraph 1 Catalan as official language; Article 4 the Constitution recognises the inviolability of the human person and of his dignity; Article 5 Universal Declaration of Human Rights binding; Article 9 paragraph 2 right to privacy (Catalan: intimitat); Article 14 the right to honour, intimacy, and one's own image is guaranteed + the right to legal protection against unlawful interference in private and family life is guaranteed; Article 15 the secrecy of correspondence and of any means of communication is guaranteed except by reasoned judicial decision; Article 17 habeas-corpus + dignity of detained persons; Article 22 equality before the law; Article 27 rights of the family + special protection of childhood; Article 28 child-protection state duty; the Tribunal Constitucional d'Andorra under Articles 95-104 hears constitutional questions. The Andorran constitutional anchor. The right to privacy in Andorra is constitutional (Articles 9 + 14 + 15) AND statutory (APDA Act 2021 + adjacent regimes) AND treaty-anchored (Convention 108 + Convention 108+ + ECHR Article 8 — Andorra ratified the ECHR 22 January 1996 in force 22 January 1996). Applies as the constitutional layer for Andorra. Treatment in §§ 3, 6, 13 below.
Constitution of the Principality of Monaco of 17 December 1962 Constitution of Monaco — the principal Monégasque constitutional document, granted by Sovereign Prince Rainier III on 17 December 1962 + substantively revised by Loi n° 1.249 du 2 avril 2002 (the "2002 Constitutional Revision" introducing legislative-Parliament-power expansions + dual-citizenship clarifications) + supplemented by subsequent constitutional revisions including Loi n° 1.396 du 14 décembre 2012. Article 1 Monaco's nature as a hereditary constitutional monarchy under the rule of law; Article 2 sovereignty; Article 8 French as official language; Article 22 each person has the right to respect for private and family life and the secrecy of correspondence; Article 24 habeas-corpus protections; Article 29 religious freedom; Article 32 equality before the law; the Tribunal Suprême de Monaco (the constitutional court) under Article 89-92 hears constitutional questions. The Monégasque constitutional anchor. The right to privacy in Monaco is constitutional (Article 22) AND statutory (Loi n° 1.165/1993 as reformed by Monaco 2024 Reform Act + adjacent regimes) AND treaty-anchored (Convention 108 + Convention 108+ + ECHR Article 8 — Monaco ratified the ECHR 30 November 2005 in force 30 November 2005). Applies as the constitutional layer for Monaco. Treatment in §§ 3, 6, 13 below.
Statuti della Repubblica di San Marino of 1600 + Dichiarazione dei Diritti dei Cittadini of 8 July 1974 Statuti + DDC — the constitutional anchors of the Most Serene Republic of San Marino: the Statuti della Repubblica di San Marino of 1600 (the oldest still-in-force written constitution in the world); supplemented by the Dichiarazione dei Diritti dei Cittadini e dei Principi Fondamentali dell'Ordinamento Sammarinese (Declaration of Citizens' Rights) — Legge n. 59 of 8 July 1974 as substantively amended (most recently by Legge Costituzionale n. 1 del 19 settembre 2019). DDC Article 1 dignity + equality; DDC Article 6 right to inviolability of the home + correspondence; DDC Article 16 right of access to information; DDC Article 18 right of access to courts; DDC Article 21 state protection of family + children; the Collegio Garante della Costituzionalità delle Norme under Legge n. 36 del 19 luglio 2002 + Legge n. 55 del 25 aprile 2003 reviews constitutionality of laws. The Sammarinese constitutional anchor. The right to privacy in San Marino is constitutional (DDC Article 6) AND statutory (Legge n. 171/2018 + Sammarinese 2025 Amendment Act + adjacent regimes) AND treaty-anchored (Convention 108 + Convention 108+ ratified 25 November 2019 in force 1 April 2020 + ECHR Article 8 — San Marino ratified the ECHR 22 March 1989 in force 22 March 1989). Applies as the constitutional layer for San Marino. Treatment in §§ 3, 6, 13 below.
Council of Europe Convention 108 Convention 108 — Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data of 28 January 1981 (ETS No. 108). Andorra acceded 1 February 2008 in force 1 June 2008; Monaco acceded 28 September 2009 in force 1 January 2010; San Marino acceded 16 November 2005 in force 1 March 2006. Article 5 quality of data + lawful basis + purpose limitation + accuracy + retention limitation; Article 6 special categories (genetic / health / sex life / political opinions / racial origin / religious or philosophical beliefs / trade-union membership / criminal convictions / criminal proceedings — Balance does NOT process special-category data); Article 7 data security; Article 8 rights of the data subject (access + rectification + erasure + remedy + supervisory-authority complaint); Article 9 exceptions and restrictions; Article 12 trans-border data flows + Additional Protocol 181 of 8 November 2001 on supervisory authorities and transborder data flows. Sets the Council of Europe foundational layer applicable in all three Microstates. Applies.
Council of Europe Convention 108+ Convention 108+ — Protocol amending the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data of 10 October 2018 (CETS No. 223). Modernised Convention 108 — substantially aligned with GDPR principles. Andorra ratified 8 February 2022 — Convention 108+ is in force for Andorra; Monaco signed 10 October 2018 — ratification status monitored under § 18 (Convention 108+ in force generally from 11 October 2023 with the 38th ratification); San Marino signed 10 October 2018 + ratified 25 November 2019 + in force for San Marino from 1 April 2020 — among the earliest contracting parties to bring Convention 108+ into force (the second contracting party after Bulgaria). Substantive provisions: Article 5 principles of legitimacy + lawful basis (consent / law / legitimate interest under specified conditions) + Article 5 paragraph 4 (b) data minimisation + storage limitation; Article 6 special categories of data; Article 7 data security including breach notification; Article 9 rights of the data subject — access + rectification + erasure + restriction + objection + right not to be subject to decisions based solely on automated processing affecting the data subject significantly (Balance does NOT engage Article 9 in respect of any Microstate resident); Article 10 additional obligations on controllers including DPIA + privacy by design + by default + DPO equivalent; Article 11 exceptions and restrictions; Article 14 trans-border flows. Sets the modernised Council of Europe layer applicable in Andorra (ratified) + San Marino (ratified + in force from 1 April 2020) + by ratification in Monaco (signed; ratification status monitored). Applies.
Andorran Llei 29/2021, del 28 d'octubre, qualificada de protecció de dades personals + APDA Act 2021 Enforcement Regulations APDA Act 2021 — published in Butlletí Oficial del Principat d'Andorra (BOPA) n° 124 of 17 November 2021; in force from 17 May 2022; the principal Andorran data-protection statute and the GDPR-aligned modernisation that replaced the prior Llei 15/2003. The APDA Act 2021 is a Llei Qualificada (qualified law — Catalan: Llei Qualificada) requiring qualified parliamentary majority under Constitution Article 57 paragraph 3. Capítol I Disposicions generals Articles 1-5 (purpose + scope + definitions); Article 3 territorial scope (GDPR-Article-3-paragraph-2-equivalent extraterritorial limb); Capítol II Principis Articles 6-12 (Article 6 lawfulness / fairness / transparency / purpose limitation / data minimisation / accuracy / storage limitation / integrity and confidentiality / accountability; Article 7 lawful bases — consent / contract / legal obligation / vital interest / public task / legitimate interest; Article 8 consent — including paragraph 3 children's-data consent at age 14cap a la informació societat — Andorra applies a 14-year digital-consent threshold; Article 9 special categories of personal data heightened regime; Article 10 criminal-convictions data); Capítol III Drets Articles 13-22 (Article 13 right to be informed; Article 14 right of access; Article 15 right of rectification; Article 16 right of erasure / right to be forgotten; Article 17 right of restriction; Article 18 right of objection; Article 19 right of data portability; Article 20 right not to be subject to certain decisions based solely on automated processing — Balance does not engage Article 20 in respect of any Andorran resident; Article 21 rights exercise + 1-month response window extendable by 2 months; Article 22 restrictions); Capítol IV Obligacions Articles 23-37 (Article 23 privacy by design + by default; Article 24 controller responsibilities; Article 25 joint controllers; Article 26 processor; Article 27 records of processing activities; Article 28 security of processing; Article 29 breach notification to APDA — without undue delay, where feasible within 72 hours from awareness; Article 30 affected-data-subject notification on high risk; Article 31 data protection impact assessment; Article 32 prior consultation; Article 33 Data Protection Officer mandatory appointment — Article 33 paragraph 1 (b) processing of children's data as core activity is a DPO trigger; Article 34 DPO designation; Article 35 position of DPO; Article 36 DPO tasks); Capítol V Transferències internacionals Articles 38-44 (Article 38 general principle — international transfer permitted under enumerated grounds; Article 39 adequacy / equivalent-protection finding by APDA; Article 40 standard contractual clauses approved by APDA; Article 41 binding corporate rules; Article 42 Convention 108+ contracting-party transfer regime; Article 43 derogations including consent + contract necessity + vital interest + public interest + legal-claim defence; Article 44 intra-group transfers); Capítol VI APDA — Agència Andorrana de Protecció de Dades Articles 45-75; Capítol VII Remedies and Sanctions Articles 76-94 (Article 76 judicial remedy; Article 77 civil compensation; Article 78 administrative sanctions — up to €20 million or 4% of worldwide annual turnover for the most serious infringements + €10 million or 2% for second-tier infringements). The principal Andorran statute. Applies in full.
Monégasque Loi n° 1.165 du 23 décembre 1993 relative à la protection des informations nominatives as reformed by Loi n° 1.565 du 3 décembre 2024 (the "Monaco 2024 Reform Act") Loi n° 1.165/1993 — published in Journal de Monaco of 31 December 1993; substantively amended on multiple occasions; comprehensively reformed by Loi n° 1.565 du 3 décembre 2024 portant réforme de la loi n° 1.165 du 23 décembre 1993 relative à la protection des informations nominatives (the "Monaco 2024 Reform Act") published Journal de Monaco n° 8722 of 13 December 2024 with most substantive provisions in force from 3 July 2025 (the seven-month vacatio legis); the principal Monégasque data-protection statute (now substantially GDPR-aligned through the Monaco 2024 Reform Act). Articles 1-3 General Provisions (purpose + scope + definitions); Article 1-1 territorial scope (introduced by Monaco 2024 Reform Act — GDPR-Article-3-paragraph-2-equivalent); Articles 4-11 Lawful bases (consent / contract / legal obligation / vital interest / public task / legitimate interest) + transparency obligations; Article 8 consent — including paragraph 4 children's-data consent at age 15Monaco applies a 15-year digital-consent threshold by alignment with French Article 45 of the Loi Informatique et Libertés; Articles 12-15 Special categories (medical / genetic / health / racial origin / political opinions / religious or philosophical beliefs / sex life / trade-union / criminal data — Balance does NOT process special categories); Articles 16-30 Data subject rights including access + rectification + erasure + restriction + objection + portability + right not to be subject to automated decisions; Articles 31-50 Controller obligations including privacy by design + by default + records of processing activities + security + breach notification to CCIN within 72 hours from awareness + affected-individual notification on high risk + DPIA + DPO mandatory appointment + DPO tasks; Articles 51-65 International transfers — adequacy-equivalent finding by CCIN + standard contractual clauses approved by CCIN + binding corporate rules + Convention 108+ contracting-party regime + derogations + intra-group; Articles 66-90 CCIN as independent supervisory authority; Articles 91-105 Remedies and Sanctions — judicial remedy + civil compensation + administrative sanctions up to €4 million or 4% of worldwide annual turnover for most serious infringements + €2 million or 2% for second-tier (lower quanta than GDPR by deliberate sovereign legislative choice). The principal Monégasque statute. Applies in full as reformed.
Sammarinese Legge 21 dicembre 2018 n. 171 — Protezione delle persone fisiche con riguardo al trattamento dei dati personali e relativa libera circolazione as amended by Decreto Delegato 16 maggio 2019 n. 64 and the Sammarinese 2025 Amendment Act (Legge 27 maggio 2025 n. 60) Legge n. 171/2018 — published Bollettino Ufficiale della Repubblica di San Marino on 21 December 2018; substantively implemented by Decreto Delegato 16 maggio 2019 n. 64 + most recently amended by Legge 27 maggio 2025 n. 60 — Modifiche alla Legge n. 171/2018 (the "Sammarinese 2025 Amendment Act"); the principal Sammarinese data-protection statute (GDPR-aligned by direct reference). Articolo 1 purpose + GDPR-aligned substantive standards by direct legislative incorporation; Articolo 2 territorial scope (GDPR-Article-3-equivalent); Articolo 3 definitions (controller / processor / data subject / personal data / processing / consent / pseudonymisation / etc.); Articoli 4-8 lawful bases (consent / contract / legal obligation / vital interest / public task / legitimate interest); Articolo 7 children's-data consent at age 14San Marino applies a 14-year digital-consent threshold by alignment with Italian GDPR national derogation under Article 2-quinquies of Decreto Legislativo 30 giugno 2003 n. 196 as amended by Decreto Legislativo 10 agosto 2018 n. 101; Articoli 9-12 special categories of personal data + criminal-data heightened regime (Balance does NOT process special categories); Articoli 13-25 data subject rights — access + rectification + erasure + restriction + objection + portability + right not to be subject to automated decisions; Articoli 26-45 controller obligations — privacy by design + by default + records of processing activities + security + breach notification to Garante San Marino within 72 hours from awareness + affected-individual notification on high risk + DPIA + DPO mandatory appointment + DPO tasks; Articoli 46-60 international transfers — adequacy-equivalent finding + standard contractual clauses + binding corporate rules + Convention 108+ contracting-party regime + derogations + intra-group + the Italy-San Marino MoU 2017 facilitative regime; Articoli 61-80 Garante San Marino as independent supervisory authority; Articoli 81-100 remedies and sanctions — judicial remedy + civil compensation + administrative sanctions up to €20 million or 4% of worldwide annual turnover for most serious infringements + €10 million or 2% for second-tier (mirroring GDPR Article 83 quanta). The principal Sammarinese statute. Applies in full as amended.
Council of Europe Convention on Cybercrime (Budapest Convention) Convention on Cybercrime — 23 November 2001 (ETS No. 185) — Andorra ratified 16 November 2014 in force 1 March 2015; Monaco ratified 17 March 2017 in force 1 July 2017; San Marino ratified 21 May 2019 in force 1 September 2019. Article 9 child-pornography offences + Article 25 + Article 27 + Article 32 + Article 35 international cooperation (mutual assistance + 24/7 point of contact + spontaneous information). Second Additional Protocol on enhanced co-operation and disclosure of electronic evidence (CETS No. 224 opened for signature 12 May 2022) — Andorra signed 12 May 2022; Monaco + San Marino signing/ratification status monitored under § 18. Applies in all three Microstates. Cross-border lawful-access for the Microstates is via the Budapest Convention 24/7 point of contact + Article 25/27/32/35 channels in addition to bilateral MLATs + Council of Europe mutual-legal-assistance instruments.
Council of Europe Convention on the Protection of Children against Sexual Exploitation and Sexual Abuse (Lanzarote Convention) Lanzarote Convention — 25 October 2007 (CETS No. 201) — Andorra ratified 19 February 2014 in force 1 June 2014; Monaco ratified 24 September 2014 in force 1 January 2015; San Marino ratified 22 March 2010 in force 1 July 2010. Article 18 sexual abuse of children; Article 19 offences concerning child prostitution; Article 20 offences concerning child pornography; Article 21 offences concerning the participation of a child in pornographic performances; Article 22 corruption of children; Article 23 — online-solicitation-for-sexual-purposes offence (the "Lanzarote online-grooming" offence). Applies in all three Microstates. The principal European child-safety treaty regime.
EU adequacy — Andorra YES. Commission Decision 2010/625/EU of 19 October 2010 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of personal data in Andorra (the "Andorra Adequacy Decision 2010") — first periodic review under GDPR Article 45(4) completed by the European Commission in January 2024 and confirmed. Facilitates EU/EEA→Andorra flow + cross-referenced in EU / EEA annex § 8. Cross-reference. Andorra holds adequacy.
EU adequacy — Monaco None at the Effective date. Adequacy assessment is pending — Monaco has long sought an adequacy decision; the Monaco 2024 Reform Act in force 3 July 2025 substantially aligned the Monégasque framework with GDPR principles in preparation for adequacy assessment. § 18 versioning trigger covers any decision. EU/EEA → Monaco transfers are governed by EU SCCs + Transfer Impact Assessment.
EU adequacy — San Marino None at the Effective date. The Memorandum of Understanding between the Republic of Italy and the Republic of San Marino on Personal Data Protection of 2017 + the integration of EU instruments via the EU-San Marino Monetary Agreement framework facilitate Italy↔San Marino flows but no formal Commission Article 45 decision has been issued. § 18 versioning trigger covers any decision. EU/EEA → San Marino transfers are governed by EU SCCs + Transfer Impact Assessment + the Italy-San Marino MoU 2017 facilitative regime.

(Any prospective Microstate regulation governing automated processing, algorithmic decisions, or related techniques — including any post-Effective-date APDA Resolution, CCIN Délibération, or Garante San Marino Provvedimento in that area, the Andorran Avantprojecte de Llei d'intel·ligència artificial (draft law on artificial intelligence before the Andorran Consell General), the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225) opened for signature 5 September 2024 (which Andorra, Monaco, and San Marino may sign/ratify on their own timetables — § 18 versioning trigger), the Monégasque Plan national de développement de l'intelligence artificielle (national strategy issued by the Monégasque Government, voluntary policy paper only), the Sammarinese Strategia nazionale per l'intelligenza artificiale (national strategy, voluntary policy paper), the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) (in force 1 August 2024 with phased application; the EU AI Act does NOT directly bind the Microstates as Eurozone-via-Monetary-Agreement non-EU-members but each Microstate may align by independent legislative choice — § 18 versioning trigger), any future Microstate primary legislation on artificial intelligence, and any successor instrument — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such Microstate regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)


3. Supervisory authorities

3.1 Andorra — APDA (Agència Andorrana de Protecció de Dades)

The Andorran supervisory authority is the Agència Andorrana de Protecció de Dades (Catalan: Agència Andorrana de Protecció de Dades, the "APDA"), the independent supervisory authority established under the APDA Act 2021 Capítol VI Articles 45-75 (continuing in modernised form the body originally established under the prior Llei 15/2003 of 18 December 2003). The APDA is the cross-cutting Andorran data-protection regulator and represents Andorra in the Council of Europe Convention 108+ Consultative Committee.

Field Value
Name Agència Andorrana de Protecció de Dades (Catalan: Agència Andorrana de Protecció de Dades, APDA)
Status Independent supervisory authority under APDA Act 2021 Capítol VI
Headquarters Carrer Doctor Vilanova 15-19, Edifici Centre de Negocis, planta -1, AD500 Andorra la Vella, Andorra
Website https://www.apda.ad/
Complaint channel APDA online complaint form at https://www.apda.ad/; email apda@apda.ad; postal address as above
Phone +376 808 115
Breach Notification APDA online breach-notification form per APDA Act 2021 Article 29 — 72 hours from awareness

3.2 Monaco — CCIN (Commission de Contrôle des Informations Nominatives)

The Monégasque supervisory authority is the Commission de Contrôle des Informations Nominatives (French: Commission de Contrôle des Informations Nominatives, the "CCIN"), the independent supervisory authority established under Loi n° 1.165/1993 Articles 66-90 as comprehensively reformed by the Monaco 2024 Reform Act. The CCIN is the cross-cutting Monégasque data-protection regulator and represents Monaco in the Council of Europe Convention 108+ Consultative Committee.

Field Value
Name Commission de Contrôle des Informations Nominatives (French: Commission de Contrôle des Informations Nominatives, CCIN)
Status Independent supervisory authority under Loi n° 1.165/1993 Articles 66-90 as reformed by Monaco 2024 Reform Act
Headquarters 2, rue Plati, 98000 Monaco
Website https://www.ccin.mc/
Complaint channel CCIN online complaint form at https://www.ccin.mc/; email ccin@ccin.mc; postal address as above
Phone +377 97 70 22 44
Breach Notification CCIN online breach-notification form per Loi n° 1.165/1993 — 72 hours from awareness

3.3 San Marino — Garante San Marino (Autorità Garante per la Protezione dei Dati Personali)

The Sammarinese supervisory authority is the Autorità Garante per la Protezione dei Dati Personali (Italian: Autorità Garante per la Protezione dei Dati Personali, the "Garante San Marino"), the independent supervisory authority established under Legge n. 171/2018 Articoli 61-80 as amended by the Sammarinese 2025 Amendment Act. The Garante San Marino is the cross-cutting Sammarinese data-protection regulator and represents San Marino in the Council of Europe Convention 108+ Consultative Committee.

Field Value
Name Autorità Garante per la Protezione dei Dati Personali (Italian: Autorità Garante per la Protezione dei Dati Personali, Garante San Marino)
Status Independent supervisory authority under Legge n. 171/2018 Articoli 61-80
Headquarters Via XXVIII Luglio, 212 — Borgo Maggiore, 47893 Repubblica di San Marino
Website https://www.garanteprivacy.sm/
Complaint channel Garante San Marino online complaint form at https://www.garanteprivacy.sm/; email info@garanteprivacy.sm; postal address as above
Phone +378 (0549) 884 100
Breach Notification Garante San Marino online breach-notification form per Legge n. 171/2018 — 72 hours from awareness

3.4 Other regulatory bodies

Body Microstate Subject matter URL / Hotline
Co-Princes of Andorra — President of the French Republic + Bishop of Urgell (Spain) AD Constitutional Heads of State; Article 43 paragraph 2 representation n/a — institutional
Govern d'Andorra — Ministeri de Justícia i Interior AD Ministry of Justice + Interior — police + criminal-justice coordination https://www.govern.ad/
Cos de Policia d'Andorra AD Andorran Police https://www.policia.ad/; Emergency 110 + General Emergency 112
Direcció de Política Lingüística AD Catalan-language regulator https://www.cultura.ad/llengua-catalana
Ministère d'État de Monaco MC Government — overall coordination https://www.gouv.mc/
Direction de la Sûreté Publique (DSP) — Cellule de Lutte contre la Cybercriminalité MC Monégasque Police + Cybercrime Cell https://service-public-particuliers.gouv.mc/; Emergency 17 + Fire 18 + Medical 15 + General Emergency 112
Direction de l'Action et de l'Aide Sociales (DAAS) MC Child welfare + protective services https://service-public-particuliers.gouv.mc/
Autorité Monégasque de Sécurité Numérique (AMSN) MC National cybersecurity authority + Monégasque CERT (CERT-MC) https://www.amsn.gouv.mc/
Segreteria di Stato per gli Affari Interni SM Ministry of Internal Affairs https://www.esteri.sm/
Polizia Civile di San Marino + Gendarmeria + Guardia di Rocca SM Sammarinese police forces Emergency 113 + Fire 115 + Medical 118
Servizio Minori — Istituto per la Sicurezza Sociale (ISS) SM Child welfare service https://www.iss.sm/
Centro Operativo di Sicurezza Informatica (COSI-SM) SM National cybersecurity authority + Sammarinese CERT (CERT-SM) via ISS
Council of Europe — Convention 108+ Consultative Committee All International Convention 108+ supervisory committee https://www.coe.int/en/web/data-protection/convention-108-and-protocol
European Data Protection Board (EDPB) All (cross-reference) EU supervisory-authority cooperation body; engages on EU/EEA→Microstate transfer matters https://edpb.europa.eu/
European Court of Human Rights (ECHR) All ECHR Article 8 right to respect for private and family life adjudication https://www.echr.coe.int/
116 111 European Common Children's Helpline AD + MC + SM European common children's helpline — implemented variably across Microstates dial 116 111
Telefono Azzurro (Italia) SM (cross-border) Italian children's emotional-support hotline (Sammarinese residents may access) https://www.azzurro.it/; +39 199 151 515 (Hotline 19696)
CRIDA — Centre de Recerca i Defensa dels Drets dels Infants AD Andorran child-protection NGO via Andorran social-welfare directory
AMIPC — Association Monégasque pour les Personnes Handicapées et leurs Amis MC Monégasque social-welfare NGO via Monégasque NGO directory

3.5 The DPO

Each Microstate's statutory framework imposes a mandatory DPO appointment for controllers and processors that meet defined criteria. For Balance:

The Balance DPO is:

The DPO's business contact is published in this Annex, in the global Privacy Policy (Privacy Policy § 1), and at balance.babayagaprogram.com — satisfying each Microstate's publicly-accessible-DPO-contact requirement + Council of Europe Convention 108+ Article 10 (entrusted-person publicly-available-contact requirement). The DPO is the contact point for the APDA + CCIN + Garante San Marino on any regulatory matter and for data subjects on rights-exercise matters. The DPO need not be a Microstate citizen or resident but must be readily accessible during European business hours per each Microstate's regulator interpretive practice.


4. Lawful bases — APDA Act 2021 Article 7 + Loi n° 1.165/1993 Articles 4-11 + Legge n. 171/2018 Articoli 4-8

Each Microstate's framework is substantially aligned with the GDPR lawful-bases catalogue (consent / contract / legal obligation / vital interest / public task / legitimate interest). Balance processes personal data of Microstate residents on the following mapping:

Processing purpose Andorra (APDA Act 2021) Monaco (Loi n° 1.165/1993) San Marino (Legge n. 171/2018) Cross-reference
Run the parental-control service the parent signed up for Article 7(b) performance of contract + Article 8 consent + Article 6 principles Article 4(b) performance of contract + Article 4(a) consent + Article 5 principles Articolo 4(b) performance of contract + Articolo 4(a) consent + Articolo 5 principles H1 § 4; H7 PA-01 – PA-08; § 7 below
Process the kid's personal data Article 8 paragraph 3 children's-data consent — Andorra digital-consent age 14 + Article 7(b) + Civil Code Article 168 parental authority Article 8 paragraph 4 children's-data consent — Monaco digital-consent age 15 + Article 4(b) + Code Civil Articles 372-389 parental authority Articolo 7 children's-data consent — San Marino digital-consent age 14 + Articolo 4(b) + Sammarinese Civil Code parental-authority provisions § 7 below; our Data Protection Impact Assessment § 6
Deliver operational alerts Article 7(b) Article 4(b) Articolo 4(b) H1 § 4; H7 PA-09; M3
Detect, prevent, and respond to security incidents Article 7(f) legitimate interest + Article 28 security Article 4(f) legitimate interest + security obligation Articolo 4(f) legitimate interest + security obligation H7 PA-15; § 13 below
Comply with legal obligations Article 7(c) legal obligation Article 4(c) legal obligation Articolo 4(c) legal obligation § 13 below; M1; § 14 below
Process VPC for the kid's data Article 7(b) + Article 8 + Article 13 Article 4(b) + Article 8 + transparency Articolo 4(b) + Articolo 7 + Articolo 13 § 7 below; A-US § 5
Process the parent's billing/subscription data Article 7(b) + consumer-protection overlay § 16 Article 4(b) + consumer-protection overlay § 16 Articolo 4(b) + consumer-protection overlay § 16 H4; § 16 below

Balance does not process special categories of personal data in respect of any Microstate resident (APDA Act 2021 Article 9 + Loi n° 1.165/1993 Article 12 + Legge n. 171/2018 Articolo 9 — racial or ethnic origin / political opinions / religious or philosophical beliefs / trade-union membership / genetic data / biometric data for the purpose of uniquely identifying a natural person / health data / data concerning sex life or sexual orientation / criminal convictions — none processed).

Balance does not collect any Microstate national or government-issued identification number — neither the Andorran Número d'Identificació Personal (NIP) issued under the Llei de Registre Civil; nor the Monégasque national identifier; nor the Sammarinese codice ISS / Codice di Sanità issued by the Istituto per la Sicurezza Sociale.


5. Children's rights overlay

Each Microstate is party to the UN Convention on the Rights of the Child — Andorra acceded 2 January 1996; Monaco acceded 21 June 1993; San Marino acceded 25 November 1991 — and to the Council of Europe Lanzarote Convention (see § 2 above). The children's regime is built up from each Microstate's data-protection framework + child-protection statute + civil-code minor-capacity doctrine + Lanzarote Convention domestication.

5.1 Definitions

For the purposes of this Annex:

Balance applies the most-protective reading across all three Microstates and obtains Verifiable Parental Consent for every Microstate kid regardless of age, using the VPC mechanism in United States annex § 5 (email-verified parent account creation + payment-method capture at subscription time + parent's affirmative in-app action of creating the kid profile and pairing the kid's device). The VPC screen for Microstate residents itemises the categories of personal data being processed, the purposes for which it is being processed, the third parties to whom it may be disclosed (sub-processors), and the data subject's rights under the applicable Microstate framework + the Council of Europe Convention 108+ + the constitutional + Lanzarote Convention overlay.

Balance does not provide a kid-self-serve consent path inside the app. The parent always consents on behalf of the kid; the kid app's UI is designed for the kid to see their own limits, schedules, tasks, and earned-time ledger, and to request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision. This is the most-protective reading of each Microstate's data-protection framework + the child-protection regime + the Lanzarote Convention + the UN CRC.

5.4 No advertising directed at children

Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising data file of any user. This is consistent with: (i) each Microstate's transparency + fairness principles (APDA Act 2021 Article 6; Loi n° 1.165/1993 Article 5; Legge n. 171/2018 Articolo 5); (ii) the Lanzarote Convention principles of child protection; (iii) each Microstate's child-protection statute (Andorra Children Rights Act 2019; Monaco Loi n° 1.382/2011 + Loi n° 1.344/2007; San Marino Legge n. 83/1990 + Legge n. 17/2004). Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.

5.5 Cooperation routes

Each Microstate has child-protection bodies + a Lanzarote-Convention national focal point. The principal cooperation routes per Microstate:

Treatment in § 14 below.


6. Microstates rights catalogue

6.1 The rights catalogue

A Microstate resident has the following rights under the applicable Microstate framework + the Council of Europe Convention 108+ Article 9:

6.2 Timeline

6.3 Identity verification

Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity. The identity-verification protocol uses the parent's existing authentication credential.

6.4 Fees

Each Microstate's framework permits the controller to charge a reasonable fee for processing a manifestly unfounded or excessive request, in particular because of its repetitive character. Balance does not charge for access in practice.

6.5 Language

A request may be submitted in Catalan / French / Italian / English. The APDA accepts Catalan + Spanish + French + English; the CCIN accepts French + English; the Garante San Marino accepts Italian + English (preferring the respective official language for procedural materials).


7. Children's data — Microstates framework

Balance processes personal data of Microstates kids under the following layered framework:

For Balance:

A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.


8. International data transfers from the Microstates

The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Microstate resident's personal data leaves the respective Microstate at the point of being uploaded to the Balance backend.

8.1 Andorra → US transfer mechanism

APDA Act 2021 Capítol V (Articles 38-44) sets out the international-transfer regime, substantially aligned with GDPR Chapter V. The principal mechanisms: - Article 39 adequacy / equivalent-protection finding by APDA — the APDA may designate countries as offering an adequate or equivalent level of protection (the APDA's published list of designated countries is at https://www.apda.ad/ — the US is NOT on the APDA-designated-adequate list at the Effective date); - Article 40 standard contractual clauses approved by APDA — APDA-approved SCCs are the principal contractual safeguard; - Article 41 binding corporate rules — n/a for Balance (no intra-group BCRs); - Article 42 Convention 108+ contracting-party transfer regime — Convention 108+ contracting-party identification overlay; - Article 43 derogations — including (a) data-subject consent given with knowledge of inadequacy + (b) necessity for performance of contract + (c) public interest + (d) legal-claim defence + (e) vital interest.

Balance relies on the following stack to satisfy APDA Act 2021 Capítol V:

8.2 Monaco → US transfer mechanism

Loi n° 1.165/1993 Articles 51-65 (as substantively reformed by the Monaco 2024 Reform Act) sets out the international-transfer regime, substantially aligned with GDPR Chapter V. The principal mechanisms: - Article 52 adequacy-equivalent finding by CCIN — the CCIN may designate countries as offering an adequate or equivalent level of protection (the CCIN's published list is at https://www.ccin.mc/ — the US is NOT on the CCIN-designated-adequate list at the Effective date); - Article 53 CCIN-approved standard contractual clauses — principal contractual safeguard; - Article 54 binding corporate rules — n/a; - Article 55 Convention 108+ contracting-party transfer regime; - Article 56 derogations — including (a) data-subject consent + (b) performance-of-contract necessity + (c) public interest + (d) legal-claim defence + (e) vital interest.

Balance relies on the following stack: - Article 56(b) performance-of-contract necessity — principal mechanism. - Article 53 CCIN-approved SCCs / written contracts with substantively-equivalent protection. - Article 56(a) parent's consent overlay — belt-and-braces. - Supplementary measures — E2EE. - Onward-transfer restrictions.

8.3 San Marino → US transfer mechanism

Legge n. 171/2018 Articoli 46-60 (as amended by the Sammarinese 2025 Amendment Act) sets out the international-transfer regime, substantially aligned with GDPR Chapter V. The principal mechanisms: - Articolo 47 adequacy-equivalent finding by Garante San Marino — the Garante's published list is at https://www.garanteprivacy.sm/ (the US is NOT on the Garante-designated-adequate list at the Effective date); - Articolo 48 Garante-approved standard contractual clauses — principal contractual safeguard; - Articolo 49 binding corporate rules — n/a; - Articolo 50 Convention 108+ contracting-party transfer regime (San Marino's Convention 108+ contracting-party status since 1 April 2020 is operative); - Articolo 51 derogations — including (a) data-subject consent + (b) performance-of-contract necessity + (c) public interest + (d) legal-claim defence + (e) vital interest; - Italy-San Marino MoU 2017 — the Memorandum of Understanding between the Republic of Italy and the Republic of San Marino on Personal Data Protection of 2017 facilitates Italy↔San Marino flows; n/a directly to the US leg but cross-referenced.

Balance relies on the following stack: - Articolo 51(b) performance-of-contract necessity — principal mechanism. - Articolo 48 Garante-approved SCCs / written contracts with substantively-equivalent protection. - Articolo 51(a) parent's consent overlay — belt-and-braces. - Supplementary measures — E2EE. - Onward-transfer restrictions.

8.4 The Microstate-to-KZ axis (controller administrative access)

The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. The Microstate-KZ axis is covered by each Microstate's contractual-safeguards framework + parent's consent overlay + performance-of-contract necessity — written processor agreements signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse, with EU-SCC substance preserved. The transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.

8.5 RoPA + supervisory-authority filings

Balance maintains the internal RoPA at our Records of Processing Activities (Article 30).


9. Data residency for Microstates residents

Question Answer
Where is the backend hosted? United States. Emergent Labs Inc. (Delaware) on US infrastructure.
Where is the MongoDB database located? United States.
Where is the proof-media storage located? United States — Google Cloud Storage us multi-region.
Where are push notifications dispatched from? United States — Firebase Cloud Messaging.
Is any Microstate resident's personal data held in their respective Microstate? No. Every Microstate resident's personal data is held in the United States. The cross-border-transfer mechanism stack in § 8 above is the legal basis for the transfer.
Where is the controller? Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor agreements.
Is there a Microstate establishment? No. Balance has no permanent establishment in Andorra, Monaco, or San Marino. Each Microstate's extraterritorial-reach limb is the basis for compliance.
Where is the supervisory authority? Andorra — APDA; Monaco — CCIN; San Marino — Garante San Marino.

The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. None of the three Microstates imposes a comprehensive data-localisation mandate on parental-control services at the Effective date.


10. Sub-processors touching Microstates-resident data

Sub-processor Role Location of processing Microstates transfer paperwork
Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer Hosts the FastAPI backend + MongoDB cluster United States APDA Act 2021 Article 40 + Loi n° 1.165/1993 Article 53 + Legge n. 171/2018 Articolo 48 written processor agreement with substantively-equivalent protection + each Microstate's parent-consent overlay per our international-transfer pack § 6; E2EE supplementary measure for proof media; Convention 108+ contracting-party overlay (each Microstate is a contracting party).
Google LLC — Google Cloud Storage (USA) Stores end-to-end-encrypted proof-media ciphertext United States (us multi-region) Each Microstate Article-equivalent SCCs (Google Cloud Data Processing Addendum) + parent-consent overlay; ciphertext-only handling.
Google LLC via Google Cloud (USA) Periodic (daily) backups of our operational database United States (us multi-region) Each Microstate Article-equivalent SCCs (Google Cloud Data Processing Addendum) + parent-consent overlay; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted.
Google LLC — Firebase Cloud Messaging Delivers push notifications United States As above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures).
Google LLC — Google Sign-In Authenticates parent Google identity (when used) United States As above.
Google LLC — Google Play Billing Processes subscription purchases United States As above + Google Play Developer Distribution Agreement.
Resend, Inc. (San Francisco, CA, USA) Delivers transactional email United States As above.

Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + each Microstate's security obligations. The full sub-processor list, with each row's processor-agreement status, is at our sub-processor register.


11. Breach notification

Each Microstate's framework imposes a 72-hour breach-notification obligation to the supervisory authority, substantially aligned with GDPR Article 33.

Audience Trigger Deadline Channel
APDA / CCIN / Garante San Marino A personal data breach — a breach of security leading to the unlawful or accidental loss / access / alteration / disclosure of personal data — that is likely to result in a risk to the rights and freedoms of natural persons (and the relevant Microstate framework permits voluntary notification for breaches unlikely to result in a risk). Without undue delay, where feasible within 72 hours from awareness of the personal data breach. Awareness is the time at which the controller has a reasonable degree of certainty that a personal data breach has occurred. Balance internal anchor: as soon as practicable but no later than 72 hours from initial discovery. APDA online portal at https://www.apda.ad/; CCIN online portal at https://www.ccin.mc/; Garante San Marino online portal at https://www.garanteprivacy.sm/
Affected individuals A personal data breach as above where the harm-likelihood analysis indicates the breach is likely to result in a high risk to the rights and freedoms of natural persons. As soon as practicable after supervisor notification, with carve-outs (data rendered unintelligible — E2EE ciphertext case; subsequent measures eliminating high risk; disproportionate effort). Direct email to the affected parent on file; in-app banner; out-of-app contact via the public-website incident page. The notification is in English, with Catalan / French / Italian versions queued for the Phase-2 locale rollout.
CSAE-specific An incident with a CSAE component. Per § 14 below + the internal runbook (M1). Each Microstate's police + child-welfare bodies + Convention-201-Lanzarote-Convention-compliant referral channels.

The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9.

11.1 Minimum content of the breach notification

The notification states: - the nature of the personal data breach, categories and approximate number of data subjects concerned, and categories and approximate number of personal data records concerned; - the name and contact details of the DPO (, named individual: ) — the contact from whom the supervisory authority may obtain additional information; - the likely consequences of the personal data breach; - the measures taken or proposed to be taken to address the personal data breach (including measures to mitigate possible adverse effects).

The English-language template lives in our breach-notification runbook § 8.1. Catalan / French / Italian versions are queued for Phase 2 locale rollout.

11.2 Non-compliance — administrative sanctions


12. Cookies, spam, and electronic direct marketing

None of the three Microstates has a dedicated ePrivacy / cookies statute equivalent to the EU ePrivacy Directive 2002/58/EC. The substantive position on cookies and electronic direct marketing is derived from each Microstate's data-protection statute consent requirement + the relevant electronic-communications statute + each Microstate's general consumer-protection framework + Council of Europe Convention 108+ Article 5 lawful-basis principles.

12.1 In-app — strictly-necessary storage only

The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent.

The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.

12.3 Electronic direct marketing — not sent

Balance does not send marketing communications to Microstates residents. The only email Balance sends to Microstates parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. Transactional messages are outside any commercial-electronic-message definition. If Balance ever introduces a marketing channel, we will comply with each Microstate's prior-consent + right-to-object framework + the relevant electronic-communications statute.

12.4 No telemarketing

Balance does not place telemarketing voice calls, SMS, or messaging-app outreach to Microstates residents.


13. Lawful-access requests and the encryption posture

Microstates authorities may serve a lawful-access request on Balance via:

13.1 Andorra

13.2 Monaco

13.3 San Marino

13.4 Encryption posture and response protocol

The Balance architectural posture interacts with these mechanisms as follows:

The full encryption posture is in our encryption-posture record.


14. CSAE reporting routes — Microstates

A Microstate resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:

14.1 Andorra

14.2 Monaco

14.3 San Marino

14.4 Lanzarote Convention focal points

Each Microstate maintains a national focal point under the Lanzarote Convention (CETS No. 201). The Council of Europe Lanzarote Committee monitors implementation and provides a cross-border-coordination forum at https://www.coe.int/en/web/children/lanzarote-convention.

14.5 INHOPE membership status

None of the three Microstates has a domestic INHOPE-member CSAM hotline at the Effective date. Cross-border CSAM reports flow through (i) each Microstate's police channels; (ii) Budapest Convention 24/7 point of contact; (iii) INTERPOL national-central-bureau channels (Andorra via Madrid/Paris; Monaco via Monaco NCB; San Marino via Rome); (iv) the international INHOPE network via neighbouring-state hotlines (Spain INCIBE / France PHAROS / Italy IPolizia.it / Spain ChildLineSP).

The full CSAE Country Routing Table is in Child Safety Standards § 8.6.


15. Complaint routes (summary)

A Microstate resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:

Authority Microstate Subject matter Address / URL
APDA — Agència Andorrana de Protecció de Dades AD APDA Act 2021 Carrer Doctor Vilanova 15-19, AD500 Andorra la Vella; https://www.apda.ad/; +376 808 115; apda@apda.ad
CCIN — Commission de Contrôle des Informations Nominatives MC Loi n° 1.165/1993 as reformed 2, rue Plati, 98000 Monaco; https://www.ccin.mc/; +377 97 70 22 44; ccin@ccin.mc
Garante San Marino — Autorità Garante per la Protezione dei Dati Personali SM Legge n. 171/2018 as amended Via XXVIII Luglio, 212 — Borgo Maggiore, 47893 San Marino; https://www.garanteprivacy.sm/; +378 (0549) 884 100; info@garanteprivacy.sm
Tribunal Constitucional d'Andorra AD Constitutional review https://www.tribunalconstitucional.ad/
Tribunal Suprême de Monaco MC Constitutional review https://www.tribunal-supreme.mc/
Collegio Garante della Costituzionalità delle Norme SM Constitutional review https://www.collegiogarante.sm/
European Court of Human Rights (ECHR) All ECHR Article 8 post-domestic-exhaustion https://www.echr.coe.int/
Council of Europe Convention 108+ Consultative Committee All Cross-Microstate cooperation matters via Council of Europe Data Protection Unit
Cos de Policia d'Andorra / DSP Monaco / Polizia Civile di San Marino AD / MC / SM Criminal complaints including CSAE + cybercrime Emergency 110 / 17 / 113
Ordinary courts All Civil compensation + judicial remedies Tribunal de Batlles (AD); Tribunal de Première Instance (MC); Tribunale Unico (SM)

A Microstate resident may always first raise the matter with us at (data access; named individual: , in his capacity as the designated DPO under each Microstate's statutory framework + Council of Europe Convention 108+ Article 10).


16. Consumer rights — Microstates consumer-protection overlay

16.1 Andorra — Llei 13/2013

The Llei 13/2013, del 13 de juny, de competència efectiva i protecció del consumidor (the "Andorra Consumer Protection Act 2013") applies to Balance's subscription flow as a consumer transaction (the parent is a consumidor within the Llei 13/2013 definition). Article 18 — 14-day right of withdrawal for distance-selling contracts (aligned with EU Consumer Rights Directive 2011/83/EU + carve-outs for digital-content services where consumer expressly consents to immediate performance and acknowledges loss of withdrawal right). Article 23-30 unfair-contract-terms screen for standard-form consumer contracts. Enforced by the Departament de Comerç i Consum at https://www.govern.ad/.

16.2 Monaco — Code de la Consommation framework

Monaco does not have a single consolidated Consumer Code but applies consumer protection through (i) the Code de Commerce + Code Civil de Monaco + Loi n° 1.383 du 2 août 2011 sur l'économie numérique (the principal e-commerce statute) + Loi n° 1.291 du 21 décembre 2004 sur la prévention de la corruption as relevant. Loi n° 1.383/2011 Article 13 — 14-day right of withdrawal for distance-selling contracts (aligned with French Code de la Consommation Article L221-18 substantive standard) + carve-outs for digital-content services where consumer expressly consents to immediate performance. Enforced by the Direction de l'Expansion Économique + Monégasque consumer-protection forum.

16.3 San Marino — Legge n. 92/2013 + Codice del Consumatore alignment

The Legge 29 luglio 2013 n. 92 — Legge sulla disciplina del commercio elettronico (the "Sammarinese E-commerce Act 2013") applies to Balance's subscription flow + the substantive standards align with the Italian Codice del Consumatore (D.Lgs. n. 206/2005) by interpretive practice. Articolo 10 — 14-day right of withdrawal for distance-selling contracts + carve-outs for digital-content services with express consumer consent to immediate performance.

16.4 Voluntary 14-day no-questions refund — meets all three Microstate floors

Balance honours a voluntary 14-day no-questions refund window via Google Play Billing, meeting the 14-day cooling-off floors of all three Microstate consumer frameworks. The 14-day refund window is documented at Subscription Terms § 20.

16.5 Minor-capacity framework

Each Microstate's civil code imposes a minor-incapacity doctrine substantially aligned with continental European civil-law tradition: - Andorra (Andorran Civil Code) — a minor (under 18) of limited capacity requires the legal representative's consent for binding contracts; an act done without that consent is voidable. - Monaco (Monégasque Civil Code Article 489)mineur (under 18) of limited capacity; binding contracts require legal-representative consent. - San Marino (Sammarinese Civil Code)minore (under 18) of limited capacity; binding contracts require legal-representative consent.

The subscription contract is between Balance and the parent (who is 18+). The kid is a beneficiary of the service supplied to the parent. Balance does not contract directly with kids.

16.6 Forum and choice of law

The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses or jurisdiction clauses that would deprive the Microstate consumer of mandatory consumer-protection law are subject to each Microstate's unfair-terms-in-standard-contracts screen + the public policy doctrine recognised by each Microstate's courts.


17. Cross-references


18. Versioning and review

This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:


End of European Microstates Bundle Country Annex (Andorra · Monaco · San Marino).

← Back to Privacy Policy · Children's Privacy Notice