Privacy Policy – Zemen Calendar

Application: Zemen Calendar

Developer: Zemen Studio

Package Name: com.ethiopiancalendar.app

Contact: filmonseare@gmail.com

Last updated: February 26, 2026

This mobile application "Zemen Calendar" (package: com.ethiopiancalendar.app) is developed and published by Zemen Studio (Filmon Seare) and provides an Ethiopian calendar service with church and event management. This policy explains how we collect, use, and protect your personal data in accordance with the General Data Protection Regulation (GDPR) and French data protection law.

1. Data Controller

The data controller for your personal data is:

Zemen Studio
Filmon Seare – Independent Developer
Paris 18e, France
Email: filmonseare@gmail.com
Phone: +33 7 80 74 40 96

Application: Zemen Calendar
Package Name: com.ethiopiancalendar.app

As the data controller, we determine the purposes and means of processing your personal data and are committed to protecting it in accordance with applicable regulations.

2. Application Features

Our application offers the following services:

2. Data Collected

2.1 Identification Data

2.2 Profile Data

2.3 Church Data

2.4 Event Data

2.5 Technical Data

2.6 Diagnostics Data

This diagnostic data is collected to improve application performance and functionality.

2.7 Payment Data

2.8 In-App Purchases

This financial data is collected solely to validate your in-app purchases via Google Play. It is not shared with third parties.

3. Use of Data

We use your data to:

4. Legal Basis for Processing (Article 6 GDPR)

In accordance with Article 6 of the GDPR, we process your personal data on the following legal bases:

4.1 Performance of Contract (Article 6.1.b)

Processing necessary for the performance of the contract you have entered into with us:

4.2 Consent (Article 6.1.a)

Processing based on your explicit consent:

You may withdraw your consent at any time by modifying your preferences in the application or by contacting us. Withdrawal of consent does not affect the lawfulness of processing carried out before such withdrawal.

4.3 Legal Obligation (Article 6.1.c)

Processing necessary to comply with our legal obligations:

4.4 Legitimate Interest (Article 6.1.f)

Processing based on our legitimate interest, respecting your rights and freedoms:

You have the right to object to this processing (see "Your Rights" section).

5. Sensitive Data (Article 9 GDPR)

Important information regarding sensitive data:

Joining a church through our application may indirectly reveal your religious beliefs, which constitutes a special category of personal data under Article 9 of the GDPR.

5.1 Nature of Sensitive Data Collected

5.2 Legal Basis for Processing Sensitive Data

In accordance with Article 9.2.a of the GDPR, we process this sensitive data only on the basis of your explicit consent, which you provide when:

5.3 Your Guarantees

6. Third-Party Services Used

6.1 Stripe

For payment processing and subscriptions. Stripe collects and processes your payment data according to its own privacy policy.

6.2 Firebase Cloud Messaging (FCM)

For sending push notifications. Google collects technical data according to its privacy policy.

6.3 SMS Services

For sending OTP verification codes.

6.4 Analytics Services

For application improvement (anonymized data only).

6.5 Expo

For managing push notifications via Expo Push Token. Expo processes device identifiers according to its privacy policy.

6.6 Google Play Billing

For validating in-app purchases. Google processes transaction data according to its privacy policy.

7. International Data Transfers

Some of our service providers are located outside the European Union. We ensure that these transfers are governed in accordance with the GDPR.

7.1 Destination Countries

Your data may be transferred to:

7.2 Applicable Safeguards

These transfers are governed by the following mechanisms, in accordance with Articles 44 to 49 of the GDPR:

7.3 Detail by Provider

Provider Country Safeguards
Stripe United States SCC + DPF certified
Google (FCM, Play) United States SCC + DPF certified
Expo United States Standard Contractual Clauses

You may obtain a copy of the applicable safeguards by contacting us at the address provided at the end of this document.

8. Data Security

We implement robust security measures:

  • Data Encryption: All data is transmitted via a secure, encrypted HTTPS connection. Data in transit is protected using TLS (Transport Layer Security) encryption.
  • Password Hashing: Use of bcrypt
  • JWT Tokens: Secure authentication with expiration
  • OTP Verification: Two-factor authentication via SMS
  • Restricted Access: Only authorized administrators have access to data
  • Secure Backups: Data backed up in encrypted form

9. Data Sharing

We never sell your personal data. We may share your data only in the following cases:

10. Your Rights (Articles 15 to 22 GDPR)

In accordance with the GDPR and French data protection law, you have the following rights:

10.1 How to Exercise Your Rights

You can exercise your rights in several ways:

We will respond to your request within one month. This period may be extended by two months for complex requests, in which case you will be informed.

10.2 Data Deletion

You can request the deletion of your data at any time:

10.3 Complaint to the CNIL

If you believe that the processing of your personal data constitutes a violation of the GDPR, you have the right to lodge a complaint with the French supervisory authority:

CNIL - Commission Nationale de l'Informatique et des Libertés
3 Place de Fontenoy, TSA 80715
75334 Paris Cedex 07, France
Website: www.cnil.fr
Phone: +33 1 53 73 22 22

11. Data Retention

We retain your personal data only for as long as necessary for the purposes for which it was collected, in accordance with Article 5.1.e of the GDPR.

11.1 Detailed Retention Periods

Data Type Retention Period Justification
Account data (name, email, phone) Duration of account + 3 years Contract performance + civil statute of limitations
Church and membership data Duration of membership + 1 year Service + dispute management
Events 2 years after the event History and statistics
Technical logs and IP addresses 12 months Security and LCEN compliance
Diagnostic data 6 months Technical improvement
Invoices and payment data 10 years Tax obligations (French Commercial Code)
Google Play purchase tokens Duration of subscription + 1 year Validation and support
Push tokens (Expo/FCM) Duration of account Notification service

11.2 Data Deletion

12. Cookies and Similar Technologies

Our mobile application does not use traditional web cookies, but may use:

These technologies are necessary for the application to function and are not used for advertising tracking purposes.

13. Protection of Minors

Compliance with French legislation:

In France, in accordance with Article 45 of the Data Protection Act and Article 8 of the GDPR, parental consent is required for minors under 15 years of age.

14. Changes to This Policy

We may update this privacy policy to reflect changes in our practices or for legal reasons. In the event of a substantial modification:

We encourage you to regularly review this policy to stay informed of our data protection practices.

15. Contact and Support

Application: Zemen Calendar

Package Name: com.ethiopiancalendar.app

Developer / Data Controller:

Zemen Studio
Filmon Seare – Independent Developer
Paris 18e, France
Email: filmonseare@gmail.com
Phone: +33 7 80 74 40 96

To exercise your rights or ask questions:

The application Zemen Calendar is available on Google Play Store.

16. Legal Compliance

This privacy policy complies with the following regulations:

In the event of a conflict between this policy and applicable regulations, the regulations shall prevail.