PRIVACY POLICY

Effective Date: November 18, 2025
Last Updated: April 8, 2026

1. INTRODUCTION

This Privacy Policy applies to the Balzam mobile application ("Service"), operated by an individual entrepreneur located in Vitebsk, Republic of Belarus ("Operator", "we", "us"). This document explains how we collect, process, and protect data globally, ensuring compliance with international standards, including the laws of the USA, the European Union, and the Republic of Belarus.

2. NO MEDICAL DATA & PROFESSIONAL DISCLAIMER

No Protected Health Information (PHI): Balzam is a business management tool, NOT a medical software. We do not knowingly collect and strictly prohibit the storage of any medical records, health conditions, or data subject to the U.S. Health Insurance Portability and Accountability Act (HIPAA) or similar global health regulations.

User Responsibility: If a User (specialist) enters health-related notes about a Client, the User assumes all legal risks. The Operator shall not be held liable for such unauthorized use of the Service.

No Professional Advice: The Service does not provide medical, legal, or financial advice.

3. DATA WE COLLECT

We collect data necessary to provide the Service functionality:

Public Profile (Users): Name, specialization, work experience, education, city, time zone, and profile photo.

Private Data: Encrypted meeting records, business notes, and chat correspondence.

Client Data: Information about Clients (Name, contacts) is entered by the User. The User acts as the Data Controller for Client data; the Operator acts as the Data Processor.

Technical Data: IP address, device type, and usage statistics via Google Firebase.

4. TECHNICAL INFRASTRUCTURE & SECURITY

Storage: All data is stored using Google Cloud (Firebase/Firestore).

Encryption: We use TLS 1.3 for data in transit and AES-256 for encryption of confidential data at rest.

Permissions: The app requests access to the Camera/Gallery only for uploading profile images and documents.

5. INTERNATIONAL DATA TRANSFERS

The Service utilizes Google Cloud (Firebase) infrastructure for data storage. Your information is stored on Google's secure servers, which may be located in the United States, Europe, or other regions worldwide. Please note that the Operator is located in the Republic of Belarus and may access or manage this data from that location to provide technical support and ensure Service operation. By using Balzam, you consent to this cross-border data management.

6. REGIONAL COMPLIANCE & RIGHTS

Regardless of your location, you have the right to access, correct, or delete your data.

For USA Residents: We comply with the COPPA (we do not collect data from children under 13) and provide rights similar to the CCPA (California) regarding data transparency and deletion.

For EU Residents: We process data based on "Contractual Necessity" and "Legitimate Interest" in accordance with the GDPR.

For Belarus Residents: This Policy fulfills the requirements of Law No. 99-Z "On Personal Data Protection."

To exercise your rights, email us at: [email protected].

7. LIMITATION OF LIABILITY

To the maximum extent permitted by law, the Operator shall not be liable for any indirect, incidental, or consequential damages (including loss of profit or data) arising from the use or inability to use the Service. The Service is provided "AS IS" without warranties of any kind.

8. GOVERNING LAW AND JURISDICTION

This Policy and any legal disputes arising from the use of Balzam shall be governed by the laws of the Republic of Belarus.

Any legal proceedings shall be conducted exclusively in the courts of Vitebsk, Republic of Belarus.

9. DATA RETENTION & DELETION

We store data as long as your account is active. Users can delete their data at any time via the app settings or by contacting our support. Upon account deletion, all associated data is permanently removed from our active databases.

10. CONTACT INFORMATION

Operator: Balzam App
Location: Vitebsk, Republic of Belarus
Email: [email protected]