Sign in
Sign in

Build, manage and publish apps for MuditaOS

Contact

Mudita sp. z o.o.

Jana Czeczota 6, 02-607 Warsaw, Poland

[email protected]

Legal & Support

Help CenterHelp CenterCookies Privacy PolicyCookies Privacy PolicyPrivacy PolicyPrivacy PolicyTerms of ServiceTerms of Service

© 2026 Mudita Sp. z o.o. All rights reserved.

Privacy Policy

Help CenterHelp Center
Cookies Privacy PolicyCookies Privacy Policy
Privacy PolicyPrivacy Policy
Terms of ServiceTerms of Service
Last updated: 5 Aug 2026

MUDITA APP STORE – PRIVACY POLICY

Version: 01.08.2026 r.

This document explains in particular what personal data we collect, how we use it, and what rights you have regarding its processing. We declare special care to protect your interests. Our goal is to ensure transparency and clarity on privacy matters so that you can feel safe while using Mudita App Store.

We encourage you to review this Privacy Policy and contact us if you have any questions or concerns.

ABOUT DOCUMENT

Please note that this Privacy Policy applies solely to the processing of personal data related to the use of the Mudita App Store. It does not cover the processing of personal data related to the use of Mudita devices, other Mudita services or Apps. Information on those can be found in the legal documentation for the respective product or service.

When you install a Provider’s App, the relevant Provider is the controller of your personal data in connection with the performance of the contract for the provision of electronic services. Any questions regarding the processing of personal data by a specific Provider should be directed to that Provider directly.

Capitalized terms used in this Policy that are not defined herein have the meanings assigned to them in the Mudita App Store – Terms of Service.

DATA CONTROLLER

The controller of your personal data is Mudita sp. z o.o., with its registered office in Warsaw (02-607), Jana Czeczota 6 street (hereinafter: the “Controller” or „We”).

For matters related to the processing of personal data, you may contact the Controller by correspondence at the above address or via the following e‑mail address: [__].

PROCESSING OF YOUR PERSONAL DATA

CONTACT

Description:

If you contact us, the Controller may process your contact details as well as any other personal data you provide during the communication.

Proposes and legal basis:

  • Responding to inquiries, conducting further correspondence.
  • Establishing, defending against, or pursuing potential claims.

The legal basis is Article 6(1)(f) of the GDPR, i.e., the Controller’s legitimate interest in handling correspondence and protecting its rights.

PROPER FUNCTIONING OF THE MUDITA APP STORE / SERVICES

Description:

The Controller processes the data of individuals using the Mudita App Store for the purpose of providing the services available within it and ensuring specific functionalities (including account creation and making Content available for download/installation).

Depending on how the Mudita App Store is used, processed data may include e.g. identification data, contact data, and technical data necessary to provide the service (e.g. system logs and device/app identifiers).

Purposes and legal basis:

  • Provision of electronic services – including creating and managing your account, providing access to the App Store, and enabling download/installation of Apps and Updates.

The legal basis is Article 6(1)(b) of the GDPR – i.e., necessity for the performance of a contract or for taking action at your request before entering into a contract.

  • Compliance with legal obligations – where processing is necessary for the Controller to comply with applicable legal obligations related to the operation of the Mudita App Store.

The legal basis is Article 6(1)(c) GDPR – i.e., processing necessary for compliance with a legal obligation to which the Controller is subject.

  • Pursuit of internal administrative purposes – including for statistical or analytical purposes, e.g., analysis of User activities and preferences to improve the functionality and quality of the services provided.

The legal basis is Article 6(1)(f) of the GDPR – i.e., the Controller’s legitimate interest in analyzing the activities of Mudita App Store Users and optimizing services.

  • Establishing, defending, or pursuing potential claims.

The legal basis is Article 6(1)(f) of the GDPR, i.e., the Controller’s legitimate interest in protecting its rights.

HANDLING REPORTS OF LEGAL VIOLATIONS / ILLEGAL CONTENT

Description:

The Controller may process your data when it is necessary to handle reports concerning legal violations or illegal Content and to take decisions/actions in relation to such reports (e.g. notices identifying alleged illegal content), and to communicate with the reporting party and/or affected users. Data may include identification data, contact data, logs/device/app identifiers, and other data included in the report.

Purposes and legal basis:

  • Processing notices and reports concerning illegal Content, taking actions and decisions in relation thereto, including on the Controller’s own initiative – covering verification, review and assessment activities aimed at identifying, investigating, preventing or addressing illegal Content or violations of applicable law or the Terms of Service.

The legal basis is Article 6(1)(c) GDPR – compliance with a legal obligation (where applicable) and/or Article 6(1)(f) GDPR – the Controller’s legitimate interest in ensuring compliance of the service and preventing misuse.

  • Establishing, defending against, or pursuing potential claims related to reports/decisions.

The legal basis is Article 6(1)(f) GDPR, i.e. the Controller’s legitimate interest in protecting its rights and defending itself against potential claims or liability.

SECURITY / ABUSE PREVENTION

Description:

The Controller may process technical data (including logs and identifiers) to ensure the security of the Mudita App Store, prevent abuse and fraud, and enforce the Terms of Service (e.g. to detect suspicious activity, protect accounts, and ensure service integrity).

Purposes and legal basis:

  • Ensuring security of the service, preventing abuse/fraud, and enforcing the Terms of Service.

The legal basis is Article 6(1)(f) GDPR – the Controller’s legitimate interests in ensuring network and information security and protecting the service and users against abuse.

OBLIGATION TO PROVIDE DATA

Providing personal data is generally voluntary, but may be necessary to achieve the purposes of processing. For example, refusing to provide your data may prevent you from creating an account or contacting Us.

DATA PROCESSING PERIOD

The period for which your personal data is processed depends on the purpose and legal basis for such processing:

  • where processing personal data in connection with the performance of a contract or taking action before entering into a contract – the data will be processed for the duration of the contract or the provision of the service;
  • where personal data is processed in connection with contacting the Controller – the data will be processed for the period necessary to review the inquiry and provide a response;
  • where personal data is processed based on the Controller’s legitimate interests – the data will be processed for as long as such interests remain valid or until an effective objection is raised, unless further retention is justified.

In certain situations, personal data may be processed for longer periods than indicated above. This applies in particular where processing is necessary to establish, pursue or defend legal claims (including for the duration of limitation periods), to ensure the security of the service, or to handle reports and decisions relating to illegal Content.

Where personal data is processed to comply with a legal obligation, it will be retained for the period required by applicable law.

Depending on the scope of the personal data and the purposes for which it is processed, different retention periods may apply simultaneously. In such cases, the longer applicable retention period shall apply.

RECIPIENTS OF DATA

Your personal data may be shared or entrusted by Mudita to third parties to the extent necessary to achieve the intended purposes. The recipients of personal data may include, in particular: (i) entities affiliated with us, (ii) IT support providers (iii) professional advisors, such as lawyers, auditors, accountants, and (iv) other entities cooperating with Mudita, if justified or necessary for the purposes of data processing.

Your personal data may be also shared with Providers whose Apps are available on Mudita App Store – but only where and to the extent it is necessary to enable a specific feature you request or use (for example where a feature requires Provider involvement). As a rule, browsing or downloading an App does not require sharing your personal data with the Provider. When you install and use a Provider’s App, the Provider becomes an independent controller for processing carried out within that App and under its own terms.

Mudita may also share your personal data to local or foreign public administration authorities and law enforcement agencies if required by law. These authorities may be located both in your country of residence and abroad.

DATA TRANSFER

Your personal data will generally be processed within the EEA. However, data may be transferred to Mudita's partners who process it outside the EEA, but only to the extent necessary for Mudita’s cooperation with these partners.

In such cases, Mudita takes all possible measures to ensure the security of the transferred personal data, including, in particular, transferring personal data to countries that the European Commission has determined, by decision, to provide an adequate level of protection. In the absence of such a decision, Mudita ensures the security of personal data through safeguards such as the standard contractual clauses approved by the European Commission.

For more information about the applied safeguards, including obtaining a copy of them, you may contact Mudita using the methods indicated in section II above.

AUTOMATED INDIVIDUAL DECISION-MAKING / PROFILING

No decisions based on automated processing of personal data, including profiling, will be made concerning you.

RIGHTS OF THE DATA SUBJECTS

In connection with the processing of your personal data, you have the following rights under applicable laws:

  • the right to access your data, including obtaining a copy of your data,
  • the right to request rectification of your data,
  • the right to restrict the processing of your data,
  • the right to request the deletion of your data (in certain situations),
  • the right to data portability for data you have provided and that is processed automatically based on your consent or a contract, e.g., to another controller,
  • the right to object to the processing of personal data – to the extent that processing is based on the legitimate interest of the controller or a third party.

If your data is processed based on consent, you have the right to withdraw your consent to the extent that the data is processed on this basis. The withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

The scope of each of these rights and the situations in which they can be exercised are determined by legal regulations. The specific right you may exercise will depend, among other factors, on the purpose and legal basis of the data processing. In order to exercise your rights, you can contact us at the details provided in section II of the Policy. We will respond to your inquiries within the timeframes provided by applicable law.

If you have concerns about how Mudita processes your personal data, you may file a complaint with the appropriate data protection authority. A list of such authorities is available at this link (https://www.edpb.europa.eu/about-edpb/about-edpb/members_en). The jurisdiction of authorities is governed by the applicable law.