Legal information

App privacy policy

How data is processed when you use Telemarie — on the device itself and in the family app — with storage locations, service providers and retention periods spelled out.

1. Scope and controller

This policy covers the Telemarie device we rent or sell and the Telemarie family app for iPhone and Android. Processing on our website is described in the separate website privacy policy at https://telemarie.de/en/privacy-policy/.

The controller within the meaning of Article 4(7) GDPR is Telemarie UG (haftungsbeschränkt), Schudomastrasse 48, 12055 Berlin, Germany; Managing Director: Jan Helwich; email: info@telemarie.de.

The people concerned are the older adults who use a Telemarie device and the relatives who use the family app.

Telemarie is a deliberately reduced device. Older adults make no configuration decisions on it; the family does that through the family app. Wherever that matters for data protection, we say so explicitly below.

2. What data we process

Account data

First name, surname, email address, password (stored only as a value that cannot be converted back) and an optional profile picture. Purpose: signing in, identifying an account and displaying it to a connected contact. Legal basis: Article 6(1)(b) GDPR (performance of the contract).

Contact connections

Which relatives are connected to which Telemarie device. A connection is created when a relative enters the senior code in the family app. Purpose: routing calls and content to the right people. Legal basis: Article 6(1)(b) GDPR.

Photos and videos with captions

What relatives send to a Telemarie device. Purpose: display in the device’s photo album. Legal basis: Article 6(1)(b) GDPR.

Responses to a photo

A heart, a thumbs-up or a short written text with which the older adult replies to an individual photo. Purpose: feedback to the sender. Legal basis: Article 6(1)(b) GDPR.

Notices

Short texts that relatives send to the device’s home screen, optionally at a chosen time. Purpose: everyday reminders. Legal basis: Article 6(1)(b) GDPR.

Content of the additional features

Photos for the digital picture frame and the memory game, saved progress in sudoku and word search, and curated video and radio lists. Purpose: providing those features. Legal basis: Article 6(1)(b) GDPR.

Connection data for video calls

The technical details two devices need in order to find each other: the network addresses of the devices involved and the supported audio and video formats. They arise while a call is being set up. Picture and sound are expressly not part of this; see section 6. Legal basis: Article 6(1)(b) GDPR.

Device and usage data

Device model, operating-system and app version, battery level, type of network connection, and the identifiers used to deliver push messages and calls. Purpose: delivering calls at all, keeping the service running and diagnosing faults. Legal basis: Article 6(1)(b) GDPR and, as far as operational reliability is concerned, Article 6(1)(f) GDPR (our legitimate interest in a working service).

Crash reports

If the app crashes, a technical report is transmitted: the point of failure in the program, device type and version. Content such as photos or texts is not included. Legal basis: Article 6(1)(f) GDPR.

Usage statistics

Anonymised information about which features are used how often, for example that a photo was sent or a call was started. No content, images or texts are transmitted. See section 10 for details.

3. Where the data is held

Your content is held exclusively within the European Union. We use Google Firebase for this and have explicitly pinned every service involved to European locations:

  • Photos, videos and thumbnails in Google Cloud Storage, location ‘EU’ (a multi-region within the European Union).
  • Accounts, contact connections, captions, responses, notices, settings and saved game progress in Google Cloud Firestore, location ‘eur3’ (multi-region Belgium and the Netherlands).
  • Connection data for video calls in the Google Firebase Realtime Database, location ‘europe-west1’ (Belgium).
  • Server-side program functions, such as delivering a call or deleting an account, in Google Cloud Functions, region ‘europe-west1’ (Belgium).

This content does not leave the European Union. Where individual technical operations cannot be confined to the EU, we say so in section 5.

4. Service providers

We use the following processors under Article 28 GDPR. Data-processing agreements are in place with all of them; we select them carefully and have secured a right to issue instructions.

  • Google Ireland Limited / Google Cloud (Firebase) — accounts, database, file storage, delivery of push messages, crash reports. This is the technical foundation of the whole application.
  • Xirsys LLC — relay server for video calls (‘TURN’) via an endpoint in the European Union. It is needed only when a direct connection between two devices fails because of the network, and it forwards only data that is already encrypted.
  • Mixpanel — evaluation of usage statistics via the provider’s European servers.
  • Hexnode — management of Telemarie devices: installing updates, device settings and remote support.

Beyond this we do not pass data to third parties unless we are legally obliged to or you have consented.

5. Processing outside the EU

Three technical operations cannot be confined to the EU because the provider offers no European restriction for them:

  • Account management (Firebase Authentication) — email address and the stored value derived from the password.
  • Crash reports (Firebase Crashlytics) — technical error reports.
  • Delivery of push messages and call signals (Firebase Cloud Messaging, and Apple’s push service on iPhones).

Content — photos, videos, captions, responses and notices — is not affected; it is held exclusively in the EU. For these operations, data-processing agreements including the standard contractual clauses recognised by the European Commission under Article 46(2)(c) GDPR are in place.

6. Video calls

A video call runs as a direct connection between the two devices involved (WebRTC). Picture and sound are encrypted with DTLS-SRTP, and the two devices negotiate the keys directly between themselves. The call is therefore end-to-end encrypted.

If the network does not permit a direct connection — behind a restrictive router, for example — a relay server in the EU is placed in between. It only forwards the already encrypted data packets; it cannot decrypt them and does not store them.

There is no recording. Neither the app nor our servers store the picture or sound of a call. There is also no function that would let us join a call in progress or listen in. All that is stored is the fact that a call was set up; missed calls are noted on the device itself only.

The connection data from call set-up is protected so that only contacts who are already connected to each other can access it.

7. Photos, videos and notices

Telemarie deliberately has no chat or messenger; there are no running text conversations. Written text arises in three places: as a caption for a photo or video, as the older adult’s response to an individual photo, and as a notice sent to the home screen.

Who sees the content

A photo, its caption and the responses to it are visible to the older adult and to the relative’s account that sent it — and to relatives holding the administrator role for that device (see section 8). Notices on the home screen, along with the contents of the digital picture frame and the games, are visible to and editable by every relative connected to that device; this is intended, so that the family can coordinate.

Access by us

In ordinary operation, Telemarie staff do not see your content. Our internal tools contain no view that displays customers’ photos, captions or notices. Technically — as with any managed service — a small number of administrative accounts could gain access, for instance to resolve a reported fault. That group is restricted, and access does not happen without cause.

Deleting

When you delete a photo, a video or a notice, the record is removed from the server immediately and permanently; it is not merely hidden. The associated image or video file is then removed by a clean-up run that deletes files no record refers to any more. After that, the periods in section 12 apply.

8. Roles in the family app

Relatives connect themselves to a Telemarie device by entering the senior code. Nobody can create a connection on someone else’s behalf.

Each device has an administrator role. It goes first to the person who connects the device initially; that person can authorise further relatives. The role represents whoever looks after the device for the older adult, and it is correspondingly far-reaching. Whoever holds it can:

  • view and change the device’s settings,
  • change the displayed name and profile picture of the older adult,
  • view the device’s contact list and remove connections,
  • and view the photos and videos that other relatives have sent to that device, together with their captions and the responses to them.

We name the last point explicitly because it surprises people: the administrator role sees the device’s entire photo album, not only its own contributions. It is limited to that one device and the relatives connected to it — there is no access to other families or other devices. We recommend granting the role only to someone the family knowingly wants to give that visibility.

Without the administrator role, a relative sees only the photos and videos they sent themselves and the responses to them. The digital picture frame, the game content and the home-screen notices remain shared.

Every item technically carries the identifier of the sending account and a timestamp — otherwise the app could not show who a photo came from. We do not analyse who uploads what and when.

9. Remote support

At your request, our support team can access the Telemarie device remotely to resolve a problem without you having to send the device in.

  • Remote support is possible only for the Telemarie device, not for the private smartphones running the family app.
  • A session takes place only if it is confirmed on the device — separately for each session. Without that confirmation there is no access. Unnoticed access is not possible.
  • What is transmitted is the device’s screen. We use remote support for that purpose only; we do not use the device’s camera or microphone during a session.
  • Whatever is visible on the screen during the session is also visible to support. Remote support therefore always takes place with a person present at the device who can end the session at any time. We do not open photo albums or notices; we work on the problem that was reported.
  • For every session we record when it took place and which device was affected. We will tell you about those sessions on request.

The legal basis is Article 6(1)(b) GDPR, because remote support forms part of the support we owe you.

10. Statistics and crash reports

To understand which features work in everyday use, we collect usage statistics through Mixpanel. Only event names such as ‘photo sent’ or ‘call started’ are transmitted, never content, images or texts. The evaluation runs on the provider’s European servers.

In the family app we ask you beforehand whether you agree. If you decline, nothing is collected. The legal basis is then Article 6(1)(a) GDPR, and you can withdraw your consent in the settings at any time with effect for the future.

On the Telemarie device we collect these statistics without a separate prompt. The reason is that the device is deliberately operated without configuration dialogs for the older adult. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is recognising operating problems and faults. You may object to this collection at any time — an informal email to info@telemarie.de is enough and we will switch it off for your device.

If the app crashes, it transmits a technical error report to Firebase Crashlytics. It contains the point of failure in the program together with device and version details, but no content. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is a stable service.

11. Retention and deletion

There is no automatic deletion period. Photos, videos, captions, responses and notices are kept until you delete them or until the account is deleted. This is intentional: the Telemarie photo album would otherwise empty itself over time.

You can delete individual items in the app at any time. Section 7 explains what that does on the server.

On cancellation, or at your request, we delete the account. That deletes: the user profile and profile picture, all photos, videos and thumbnails sent, together with their captions and responses, the notices, the contact connections — including those held by connected relatives — the device settings, the contents of the digital picture frame, saved game progress and game content, the curated video and radio lists, the senior code, and the identifiers used to deliver push messages.

Deletion in the live system happens immediately, within a few minutes. The data is finally removed from all backup systems after 30 days at the latest; see section 12.

How to request deletion and obtain confirmation of it is described at https://telemarie.de/en/data-deletion/.

Separately from this, we retain invoices and accounting records for as long as statutory retention periods require — ten years under section 147(1) of the German Fiscal Code and six years under section 257(1) of the German Commercial Code. Those records contain no content from the app.

12. Backups

So that data is not lost through a technical fault, it is backed up. All backups are held in the same European region as the data itself and expire automatically; no intervention is needed for that, and none is possible.

  • Photos and videos: a deleted file can still be restored at the storage provider for 30 days and is then removed permanently.
  • Database (accounts, contacts, captions, responses, notices, settings): a daily backup with a retention period of 30 days.
  • In addition, there is a 7-day window within which an earlier state of the database can be restored.

13. Your rights

Under the GDPR you have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and objection to processing based on a legitimate interest (Article 21). You may withdraw any consent you have given at any time with effect for the future.

To exercise these rights, contact us informally at info@telemarie.de or by telephone on +49 30 57712725. On request we will confirm a deletion in writing.

You also have the right to lodge a complaint with a data-protection supervisory authority (Article 77 GDPR). The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information.

We do not use automated decision-making or profiling.

14. Data security

All connections between the apps and our servers are encrypted. Who may read which records — contacts, captions, responses, notices, settings — is checked by the server on the basis of the account and the existing contact connections, not by the app. The image and video files themselves are held at randomly generated addresses that cannot be guessed. Video calls are additionally end-to-end encrypted; see section 6.

Telemarie devices run in a locked operating mode in which no third-party applications can be installed, and they receive their updates through managed device administration.

Last updated: September 2026