Privacy Policy

Effective date: 01 March 2026

Older versions of this Privacy Policy are available in our archive here.

LadyDays is built around a simple idea: your body and your data deserve respect. We do not sell your personal data. We are established in the European Union (EU) and we apply the requirements of the GDPR (General Data Protection Regulation) as our baseline standard, regardless of where you live.

This Privacy Policy explains how we collect, use, store, and share personal data when you use:

  • the LadyDays mobile application (the “App”),
  • the website (the “Website”), and
  • any related services, features, and content we provide (all together, the “Services”).

Please also review our Terms of Service.

1. Updates to this policy

We may revise this Privacy Policy from time to time. We review it at least annually and update it when needed. If changes materially affect how we handle your personal data, we will notify you in the App or by email.

The current version is always available in the App and on the Website.

2. Where your data is stored

We store and process our core systems on servers located in the European Union (EU).

3. Personal data we collect

We collect personal data:

  • you provide to us,
  • we collect automatically when you use the App, and
  • we receive from third parties (for example, when you use social login).

3.1 Data you provide directly

Depending on how you use the App, you may provide:

Account and profile details

  • name
  • email address
  • birth month and year
  • password (if you sign up with email)
  • location (general, such as country)
  • time zone
  • language

Well-being and cycle-related information (health-related data)

  • menstrual cycle details
  • symptoms you log (including pain)
  • cosmetics usage logs
  • optional measurements (for example weight and height)

We use this information to provide App functionality (including insights and cycle predictions) and to improve the Services.

3.2 Data collected automatically

When you use the App, we may collect:

Device and technical data

  • device model
  • operating system and version
  • unique device identifiers
  • device accessibility settings (where available from the operating system)
  • mobile operator, network information
  • device storage or device system information (as provided by your device/OS)

Approximate location signals

  • IP address (used to infer an approximate location)
  • country
  • time zone (We do not collect precise GPS location).

Usage data

  • how often you use the App
  • which screens/features you use and how you interact with them

Your device or platform provider may also collect data for their own purposes under their own policies.

3.3 Data from external sources

We may receive personal data from third parties, such as:

  • social login providers (Facebook/Meta, Google), and/or
  • service providers that support analytics and statistics.

Where this happens, we use that information to operate the App, improve features, and personalize your experience.

4. Why we use your data and the legal bases

Under the GDPR (General Data Protection Regulation), we need a lawful basis for processing your personal data. Depending on what you do in the App, we rely on one or more of the following:

4.1 Consent

We rely on your consent to process health-related data (special category data). You can withdraw consent at any time by deleting your account in the App settings or by contacting us.

4.2 Contract

We process personal data as necessary to provide the Services to you and manage your account. This includes administration, account management, and delivering core features.

4.3 Legitimate interests

We may process certain data to operate, maintain, and improve the Services, including to:

  • identify and fix bugs
  • monitor performance and reliability
  • protect the App through security measures (for example vulnerability scanning)
  • analyze aggregated usage trends
  • communicate with you about subscriptions (if applicable)

When we rely on legitimate interests, we assess and balance our interests against your rights and freedoms.

4.4 Legal obligations

We may process and retain certain information to meet legal and regulatory requirements.

5. Key processing principles

We apply the following principles:

Purpose limitation and data minimization: we only collect and use personal data that is relevant for specific purposes described in this policy.

No sale of personal data: we do not sell or rent your personal data for money.

6. How we share personal data

We only share personal data in the situations described below.

6.1 Service providers (processors)

We use trusted providers to help us operate the Services. These providers process personal data on our behalf under contractual obligations.

Hetzner Cloud (hosting): We use Hetzner Cloud for hosting in EU data centers. Data stored is encrypted by LadyDays. Hetzner's Privacy Policy

Mailgun (email delivery): We use Mailgun to send emails such as newsletters, surveys, and notifications. Mailgun's Privacy Policy

6.2 Social logins

You can create an account or sign in using Facebook (Meta) or Google. If you use social login, we receive limited account information from that provider.

Facebook Login (Meta):

  • We may receive basic profile data such as name, email address, and profile picture (depending on what you allow).
  • Meta’s Privacy Policy
  • You control what is shared through your Facebook account settings.
  • We do not exchange health data with Meta.

Sign in with Google:

  • We may receive basic account data such as your email address (and possibly your name, depending on your settings).
  • Google's Privacy Policy
  • You can manage permissions in your Google account.
  • We do not exchange health data with Google.

These providers may process data on servers outside the EU.

6.3 Legal and business-related disclosures

We may preserve or disclose personal data where we believe it is reasonably necessary to:

  • comply with law, subpoenas, court orders, or legal process
  • protect the security and integrity of the Services and our users
  • establish, exercise, or defend legal claims
  • complete a merger, acquisition, transfer, or reorganization

7. International transfers

If personal data is transferred outside the EEA (European Economic Area), we take steps to protect it, including:

  • using SCCs (Standard Contractual Clauses) under Art. 46 GDPR (General Data Protection Regulation) where appropriate, and/or
  • using providers certified under the EU–US Data Privacy Framework (where relevant).

Find more about SCCs here.

8. Retention: how long we keep your data

We keep personal data only as long as necessary for the purposes described in this policy, unless a longer period is required by law.

Account deletion / erasure requests:
You can request deletion through the App settings or by contacting support@ladydayscosmetics.com. We typically respond within one month. Complete deletion from certain backup systems can take up to 90 days. Once deletion begins, it cannot be reversed because identifiers are removed/unlinked.

Deleting the App / inactivity:
If you delete the App or stop using it, we may retain your data for up to three years in case you reinstall and return. After three years of inactivity, we delete your personal data. You can request earlier deletion at any time.

Exceptions:
We may need to retain limited data where required or permitted by law (for example, legal obligations, claims handling, or certain research/statistical purposes under applicable safeguards).

8.1 How we delete data

We use standard secure deletion methods designed to permanently remove personal data from our systems. This may include automated deletion requests to processors acting on our behalf.

9. Your privacy rights

We aim to provide GDPR-level rights to all users.

You (or an authorized representative) may have the right to:

  • access your personal data
  • correct inaccurate data
  • restrict processing in certain cases
  • data portability (receive your data in a structured, portable format, such as .json)
  • delete your personal data
  • object to certain processing (for example, direct marketing)

9.1 How to exercise your rights

Email us at support@ladydayscosmetics.com or use the App settings (where available) to request deletion or make changes.

We may need to verify your identity (usually by confirming requests from the email address associated with your account). If a request is unclear, we may ask for additional information. We may refuse requests that are manifestly unfounded or excessive, as permitted by law.

You may also have the right to lodge a complaint with your local data protection authority.

10. Security

We use technical and organizational measures designed to protect personal data from loss, misuse, and unauthorized access. Measures may include:

  • encryption in transit and at rest
  • security testing and vulnerability scanning
  • integrity protections
  • role-based access controls and internal policies
  • privacy impact assessments where appropriate

No system is perfectly secure. Please keep your password confidential and consider using device-level security (passcode/biometrics) and a password manager.

10.1 Security incidents

If a breach occurs and notification is required by law, we will notify affected users and/or post a notice. We may take protective steps such as forcing logout or resetting passwords where appropriate.

Report security concerns to support@ladydayscosmetics.com.

11. Children’s privacy

The Services are not intended for children and we do not knowingly collect personal data from anyone under 16.

For legal and safety reasons, residents of the EEA (European Economic Area), UK (United Kingdom), Canada, and India must be at least 16 to use the Services.

If you believe a child is using the Services, please email us at support@ladydayscosmetics.com.

12. Communications

We may contact you via email, in-app messages, pop-ups, or push notifications about:

  • service-related updates and account messages
  • offers, promotions, rewards, and events (marketing)

Marketing opt-out:
You can unsubscribe from marketing emails using the link in the email. Opting out of marketing does not stop essential service messages. Push notifications can be disabled in your device settings. We may request additional consent for certain types of communications where required.

We may also communicate via third-party platforms (for example, social media) where you engage with us.

12.1 Social media presence

If you interact with us on social networks, we may process information like your username, profile picture, and public comments/posts about LadyDays for engagement and community management.

13. Contact us

If you have any questions or concerns about your privacy, you may contact us at:

LadyDays Cosmetics d.o.o
Pod Gradiscem 7
2000 Maribor
Slovenia
European Union (EU)

Questions or requests: support@ladydayscosmetics.com

You can also contact your local data protection authority. A list of local data protection authorities is available here.