Privacy Policy
1. Information on the collection of personal data and contact details of the controller
1.1 We are pleased that you are using our application (hereinafter the "App") or visiting our website momtick.com. Below we inform you about how your personal data is handled when you use our App and our website. Personal data is any data by which you can be personally identified. 1.2 The controller for data processing relating to this App and this website within the meaning of the General Data Protection Regulation (GDPR) is Witwaters Nova e.K. Owner: Tim Kneib, Pestalozzistraße 25, 22305 Hamburg, Germany, phone: +49 40 22634555, e-mail: info@witwaters.com. The controller responsible for the processing of personal data is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data. 1.3 This policy applies to users in the European Economic Area, the United Kingdom and Switzerland. Additional information that applies specifically to the United Kingdom and Switzerland can be found in sections 9 and 10.
2. Use of our mobile App
2.1 Downloading from the app store
When you download our mobile App from an app store, the necessary information is transmitted to that app store, in particular the user name, e-mail address and customer number of your account, the time of the download, payment information and the individual device identifier. We have no influence over this data collection and are not responsible for it. The controller is the respective operator of the app store (Apple or Google). We process the data only insofar as it is necessary for downloading the mobile App to your mobile device.
2.2 Your records stay on your device
All entries you record in the App — in particular your contraction records, your name and your settings — are stored exclusively locally on your device. The App does not transmit this data either to us or to third parties. At no time do we have access to it.
This applies expressly also insofar as these entries qualify as health data within the meaning of Art. 9 GDPR. We do not process any special categories of personal data, because this data never reaches us.
The App contains no user account and no registration. There is no server on which your records would be stored.
If you delete the App from your device, the locally stored records are deleted as well. Whether your records were previously included in a backup of your operating system (for example an iCloud backup or a Google backup) depends on your device settings and lies outside our sphere of influence.
2.3 Sharing your log
The App can generate a PDF from your records. The PDF is created on your device and handed over to the sharing function of your operating system. There you decide yourself whether and to whom you pass it on (for example by e-mail, messenger or print).
This process does not run via our servers. We have no insight into it and no access to the generated file. The provider of the service you select is responsible for any further processing.
2.4 No advertising, no tracking, no automated decision-making
The App contains no advertising, analytics or tracking services and no third-party services for evaluating your usage behaviour. Automated decision-making including profiling within the meaning of Art. 22 GDPR does not take place.
2.5 Diagnostic data from your operating system
Independently of our App, Apple or Google may collect crash and diagnostic reports, provided you have activated this in your device settings. This collection is carried out by the respective operating system provider under its own responsibility. We do not retrieve such reports.
3. Use of our website
The processing described in this section relates exclusively to visits to our website momtick.com. Our App contains none of these services; it neither accesses our website nor transmits data to any of the providers named here. For processing within the App, see section 2.
3.1 Data collection when you visit our website
When using our website for information only, i.e. if you do not register or otherwise provide us with information, we only collect data that your browser transmits to our server (so-called "server log files"). When you visit our website, we collect the following data that is technically necessary for us to display the website to you:
- Our visited website
- Date and time at the moment of access
- Amount of data sent in bytes
- Source/reference from which you came to the page
- Browser used
- Operating system used
- IP address used (if applicable: in anonymized form)
Data processing is carried out in accordance with Art. 6 (1) point f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. The server log files are stored and evaluated exclusively at the hosting provider.
3.2 Encryption
This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content. You can recognize an encrypted connection by the character string https:// and the lock symbol in your browser line.
3.3 Hosting and content delivery network
For the hosting of our website and the display of the page content, we use the system of the following provider: Netlify, Inc., 2325 3rd St #215, San Francisco, USA. All data collected on our website is processed on the provider's servers. We have concluded an order processing agreement with the provider, ensuring the protection of our site visitors' data and prohibiting unauthorised disclosure to third parties. For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
3.4 Web analysis service: Cloudflare Web Analytics
This website uses the web analytics service provided by the following provider: Cloudflare, Inc., 101 Townsend St. San Francisco, CA 94107, USA. To protect site visitors, the provider uses a pseudonymized visitor identifier to enable various analyses of site usage within a short timeframe of no more than 24 hours. This visitor identifier is a randomly generated, time-limited hash value created based on a reduced set of technical attributes. These include, in particular, the user agent (information regarding the browser and operating system) and the anonymized IP address, which is processed solely for the duration of the analysis and subsequently discarded. In the event that personal data is processed, such processing is based on our legitimate interest in the statistical analysis of usage behavior for optimization purposes, in accordance with Art. 6 (1) point f GDPR. In such cases, you may permanently object to the future collection and storage of your visitor data by notifying us. We have concluded an order processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorised disclosure to third parties. For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
4. In-App purchase
The App contains a one-off in-app purchase with which you unlock unlimited use.
The purchase is processed exclusively via the payment function of your operating system — via Apple's StoreKit framework or via Google Play Billing. We deliberately do not use any additional service provider for purchase processing or revenue analytics. There is therefore no transfer to a third party going beyond your existing relationship with Apple or Google.
Your payment data is processed solely by the operator of the app store; Apple or Google is the controller in this respect. We receive neither your name nor your e-mail address nor your payment data, but only aggregated sales statistics from Apple or Google without reference to individual persons.
The proof of your purchase remains on your device. In addition, the App records there that the unlock has taken place, so that it also applies without an internet connection. If you restore your purchase after changing device or reinstalling, the App queries only your app store for this purpose.
The legal basis for the processing on your device is Art. 6(1)(b) GDPR (performance of the purchase contract).
5. Contacting us and feedback
5.1 When you contact us via the feedback form in the App or by e-mail, personal data is collected: your message and — only if you provide it voluntarily — your e-mail address for our reply. This data is stored and used exclusively for the purpose of answering your enquiry and for the associated technical administration.
The legal basis is our legitimate interest in answering your enquiry pursuant to Art. 6(1)(f) GDPR. Where your enquiry aims at the conclusion or performance of a contract, Art. 6(1)(b) GDPR is an additional legal basis.
Your records from the App are not transmitted in this process. Only the text you have entered is transmitted.
5.2 Service providers used
For transmitting your message and sending it to our support mailbox, we use the following processors:
- Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare operates the interface through which your message is received and immediately forwarded. Your message is not stored permanently at Cloudflare. Cloudflare is certified under the EU-U.S. Data Privacy Framework; the European Commission's Standard Contractual Clauses apply in addition.
- Mailjet SAS, 13-13 bis rue de l'Aubrac, 75012 Paris, France (Sinch group), for sending e-mail. Mailjet stores personal data exclusively in data centres within the European Union (Frankfurt am Main, Germany, and Saint-Ghislain, Belgium).
We have concluded data processing agreements pursuant to Art. 28 GDPR with both providers.
5.3 Deletion
Your data will be deleted once your enquiry has been dealt with conclusively. This is the case where it can be inferred from the circumstances that the matter concerned has been definitively clarified, provided that no statutory retention obligations prevent deletion.
6. Rights of the data subject
6.1 Applicable data protection law grants you comprehensive data subject rights vis-à-vis the controller with regard to the processing of your personal data (rights to information and intervention), about which we inform you below:
- Right of access pursuant to Art. 15 GDPR: In particular, you have a right to information about your personal data processed by us, the purposes of processing, the categories of personal data processed, the recipients or categories of recipients to whom your data has been or will be disclosed, the envisaged storage period or the criteria for determining that period, the existence of a right to rectification, erasure, restriction of processing, objection to processing, complaint to a supervisory authority, the origin of your data where it was not collected by us from you, the existence of automated decision-making including profiling and, where applicable, meaningful information about the logic involved and the scope and intended effects of such processing for you, as well as your right to be informed about the safeguards pursuant to Art. 46 GDPR in the event of your data being transferred to third countries;
- Right to rectification pursuant to Art. 16 GDPR: You have a right to the immediate rectification of incorrect data concerning you and/or the completion of your incomplete data stored by us;
- Right to erasure pursuant to Art. 17 GDPR: You have the right to demand the erasure of your personal data where the conditions of Art. 17(1) GDPR are met. However, this right does not exist in particular where processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of legal claims;
- Right to restriction of processing pursuant to Art. 18 GDPR: You have the right to demand the restriction of the processing of your personal data for as long as the accuracy of your data, which you contest, is being verified; where you refuse the erasure of your data on account of unlawful processing and instead demand the restriction of the processing of your data; where you need your data for the establishment, exercise or defence of legal claims after we no longer require this data once the purpose has been achieved; or where you have objected on grounds relating to your particular situation, as long as it has not yet been established whether our legitimate grounds override yours;
- Right to notification pursuant to Art. 19 GDPR: Where you have asserted the right to rectification, erasure or restriction of processing against the controller, the controller is obliged to communicate this rectification or erasure of the data or restriction of processing to all recipients to whom the personal data concerning you was disclosed, unless this proves impossible or involves disproportionate effort. You have the right to be informed about these recipients.
- Right to data portability pursuant to Art. 20 GDPR: You have the right to receive your personal data which you have provided to us in a structured, commonly used and machine-readable format, or to demand its transmission to another controller, insofar as this is technically feasible;
- Right to withdraw consent given pursuant to Art. 7(3) GDPR: You have the right to withdraw consent to the processing of data once given at any time with effect for the future. In the event of withdrawal, we will delete the data concerned without delay unless further processing can be based on a legal ground for processing without consent. The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of the consent up to the point of withdrawal;
- Right to lodge a complaint pursuant to Art. 77 GDPR: If you consider that the processing of personal data concerning you infringes the GDPR, you have the right — without prejudice to any other administrative or judicial remedy — to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, your place of work or the place of the alleged infringement. The authority responsible for us is the Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany, https://datenschutz-hamburg.de. Details of the supervisory authorities in the United Kingdom and Switzerland can be found in sections 9 and 10.
6.2 RIGHT TO OBJECT WHERE WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF OUR OVERRIDING LEGITIMATE INTEREST IN THE CONTEXT OF A BALANCING OF INTERESTS, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THIS PROCESSING WITH EFFECT FOR THE FUTURE ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION. IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA CONCERNED. HOWEVER, WE RESERVE THE RIGHT TO CONTINUE PROCESSING IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR WHERE THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS.
7. Duration of storage of personal data
The duration of storage of personal data is determined by the respective legal basis, the purpose of processing and — where applicable — additionally by the respective statutory retention period (for example retention periods under commercial and tax law).
The records you enter in the App are stored by you alone on your device. They are deleted when you delete them in the App or remove the App from your device. We can neither access this data nor delete it.
Enquiries submitted via the feedback form or by e-mail are deleted as soon as your request has been conclusively clarified and no statutory retention obligations prevent deletion.
The server log files of our website (section 3.1) are deleted as soon as they are no longer required to ensure the secure and stable operation of the website. The visitor identifier used for reach measurement (section 3.4) expires after no more than 24 hours.
Where statutory retention periods exist for data processed in the context of legal or quasi-legal obligations on the basis of Art. 6(1)(b) GDPR, this data is routinely deleted after expiry of the retention periods, provided it is no longer necessary for the performance or initiation of a contract and/or we no longer have a legitimate interest in its continued storage.
Where personal data is processed on the basis of Art. 6(1)(f) GDPR, this data is stored until you exercise your right to object pursuant to Art. 21(1) GDPR, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
Unless otherwise stated in the other information in this policy on specific processing situations, stored personal data is otherwise deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.
8. Data security, data protection officer, minors
8.1 We take appropriate technical and organisational measures to protect your data against loss, unauthorised access and manipulation (Art. 32 GDPR, Art. 8 FADP). Your feedback message is transmitted exclusively with transport encryption (TLS).
8.2 We have not appointed a data protection officer; the statutory conditions for doing so are not met. For all data protection matters you can reach us using the contact details given in section 1.2.
8.3 The App is not directed at children under the age of 16. We do not knowingly collect personal data from children.
9. Additional information for users in the United Kingdom
9.1 Insofar as you are located in the United Kingdom, the UK GDPR in conjunction with the Data Protection Act 2018 applies to the processing of your personal data. The articles and rights referred to in this policy apply accordingly under the UK GDPR.
9.2 The competent supervisory authority is the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom, phone +44 303 123 1113, https://ico.org.uk. You have the right to lodge a complaint there at any time.
9.3 We have not designated a representative in the United Kingdom pursuant to Art. 27 UK GDPR. Our processing is only occasional, does not include large-scale processing of special categories of personal data and is unlikely to result in a risk to the rights and freedoms of natural persons; the exemption under Art. 27(2)(a) UK GDPR therefore applies.
9.4 Personal data from the United Kingdom is processed by us in Germany. Adequacy regulations of the United Kingdom are in place for the European Economic Area. Insofar as data is transferred to Netlify, Inc. or Cloudflare, Inc. in the United States of America in the context of accessing our website (sections 3.3 and 3.4) or of contacting us (section 5.2), that transfer relies on the UK Extension to the EU-U.S. Data Privacy Framework and, in addition, on the ICO's International Data Transfer Addendum to the Standard Contractual Clauses.
10. Additional information for users in Switzerland
10.1 Insofar as you are located in Switzerland, the Swiss Federal Act on Data Protection (FADP) applies to the processing of your personal data. Where this policy refers to the GDPR, the corresponding provisions of the FADP apply to you accordingly; the terms "personal data", "processing" and "controller" have an equivalent meaning under both laws.
10.2 Justification for processing
Under Swiss law, the processing of personal data by private persons is generally permitted, provided there is no breach of personality rights pursuant to Art. 30 FADP. Insofar as we invoke a legitimate interest in this policy, we base the processing on Art. 31(1) FADP. The processing in connection with the in-app purchase is directly connected with the conclusion and performance of a contract with you (Art. 31(2)(a) FADP).
10.3 Disclosure of personal data abroad (Art. 19(4) FADP)
Disclosure abroad takes place when you access our website and when you contact us via the feedback form or by e-mail. The following countries are concerned:
- Germany: processing of your enquiry at our registered office and storage at our e-mail service provider. The Swiss Federal Council has determined that Germany provides an adequate level of data protection (Annex 1 to the Data Protection Ordinance, SR 235.11).
- France and Belgium: registered office and data centre of the e-mail service provider Mailjet SAS. The Federal Council has determined an adequate level of data protection for both countries.
- United States of America: hosting of our website by Netlify, Inc., reach measurement by Cloudflare, Inc. as well as receipt and forwarding of your message by Cloudflare, Inc. The United States of America does not provide a generally adequate level of data protection. The disclosure relies on the Swiss-U.S. Data Privacy Framework, under which both companies are certified, and, in addition, on Standard Contractual Clauses.
Your contraction records entered in the App are not disclosed abroad, because they do not leave your device.
10.4 Your rights under the FADP
You have, in particular: the right of access (Art. 25 FADP), the right to data release and data portability (Art. 28 FADP), the right to rectification of incorrect data (Art. 32(1) FADP) as well as the right to demand the deletion or destruction of your data or to object to the processing (Art. 32(2) FADP).
10.5 Competent authority
The competent authority is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland, https://www.edoeb.admin.ch. You may contact the FDPIC at any time.
10.6 Representative in Switzerland
We have not designated a representative in Switzerland pursuant to Art. 14 FADP, as we process personal data neither on a large scale nor regularly, and the processing does not entail a high risk to the personality of the data subjects.
11. Language
This English version is provided for users outside Germany and is intended to fulfil our information obligations under the GDPR, the UK GDPR and the Swiss FADP in a language you can understand. A German version of this policy is also available on request and at the same address. In the event of any discrepancy, the version presented to you at the time of use applies to you.
Version: 14 August 2026