1. What this document covers
AllAbout is a mobile app for internal communication in companies, aimed primarily at employees who do not have a company computer or a company e-mail address. An employer (or another organisation, such as a university or a foundation) uses it to give its employees news, work schedules, requests, courses, chat, sports challenges and other features it chooses to enable.
This document describes how Expansio Sp. z o.o. - the developer and operator of the AllAbout app - processes the personal data of people who use the app available in Google Play and the App Store under the name AllAbout, and of visitors to the zadbajokomunikacje.pl website. The document is publicly available at the permanent address zadbajokomunikacje.pl/privacy-policy.html and inside the app.
If you use an app published under your employer's own brand (an app with a different name, built on the AllAbout platform), your employer may use its own terms of use and its own privacy notice. In that case this document supplements the employer's information as regards the role of Expansio.
2. Who the data controller is
The controller of personal data processed in connection with the operation of the AllAbout app is Expansio Sp. z o.o., with its registered office in Poznań (60-685), Poland, at ul. Królewska 21/8, entered in the Register of Entrepreneurs of the National Court Register kept by the District Court Poznań - Nowe Miasto i Wilda in Poznań, 8th Commercial Division of the National Court Register, under KRS number 0000611872, tax ID (NIP) 9721262893, statistical number (REGON) 364151889, share capital PLN 5,000 (hereinafter "Expansio", "we").
The role of your employer. Your account in the app is created for you by your employer or by the organisation that has deployed AllAbout (hereinafter the "Employer"). With regard to the data the Employer enters into the app and processes in connection with your employment (e.g. your name, employee number, assignment to a department or shift, the content it publishes), the Employer is a separate data controller and Expansio processes that data on the Employer's behalf under a data processing agreement. The Employer should provide you with its own information about data processing. For matters that depend on the Employer's decisions (e.g. who has access to the app, which modules are enabled) please contact the Employer.
Expansio independently decides how data is processed to the extent necessary to run the app, keep it secure, handle user requests and publish the app in the app stores - and in that respect it is the controller to which this policy applies.
3. Data protection contact
For any matter concerning your personal data you can contact us:
- by e-mail: office@expansio.pl,
- by post: Expansio Sp. z o.o., ul. Królewska 21/8, 60-685 Poznań, Poland.
Data protection at Expansio is the responsibility of a designated personal data protection specialist, who can be reached through the e-mail address above. Expansio has not appointed a Data Protection Officer within the meaning of Article 37 GDPR, as it is not obliged to do so.
4. What data we process
The scope of data depends on which features of the app the Employer has enabled and which ones you use. The app does not access private data on your phone (contacts, photos, text messages, other apps) except in the situations described below, in which you yourself grant it the relevant permission.
4.1. Account and identification data
- first name and surname, login (e-mail address or employee number), password (stored only in encrypted, hashed form),
- organisational data assigned by the Employer: plant, department, group, shift, position, country or language - used to direct content to the right people,
- optionally: phone number, profile photo, private e-mail address - only if you provide them yourself.
4.2. Content you create in the app
- comments, reactions, posts, notices on the notice board, messages in chat and group channels,
- photos and videos you add yourself (e.g. to a notice, a report or a sports activity),
- answers in surveys and quizzes, submissions and requests in modules enabled by the Employer (e.g. leave requests, improvement suggestions, sign-ups for events and training), progress in courses,
- questions you ask the AI assistant, if the Employer has enabled that feature.
4.3. Data made available to you by the Employer in the app
The Employer may make documents and information concerning you available in the app (e.g. your work schedule, HR information, information about benefits). Their scope is determined by the Employer. Expansio only stores and displays them to you.
4.4. Physical activity data
Step count read from Health Connect (Android) - and nothing else; step count, workouts and workout routes read from Apple Health (iOS); activities recorded in the app (including a GPS route, if you start recording yourself); activities added manually, and data from sports services you connect yourself (e.g. Garmin, Strava, Polar, Suunto). Details in section 6.
4.5. Technical data and phone permissions
- Push notifications: a device identifier (token) needed to deliver notifications; you can turn them off in your phone's settings or in the app.
- Precise location (GPS): only with your consent, given in the operating system's permission dialog, and only in two situations: (1) when you start recording the route of an activity in a sports challenge - the route coordinates are then sent to our server and stored there together with the activity; (2) when you use the Navigation screen - your current position is used to work out a route in Google Maps and is not stored on our server. The app does not collect location in the background - it is read only while the app is open and you have started one of these functions yourself. Details and how to delete stored routes: section 6.
- Camera and photo library: only with your consent, when you add a photo or video yourself.
- Technical data: device model, operating system and app version, language, IP address and server event logs (date and type of request, error messages) - needed for operation, security and troubleshooting.
5. Purposes and legal bases of processing
| Purpose | Data | Legal basis |
|---|---|---|
| Providing you with the app and its features: sign-in, displaying content, chat, requests, courses, notifications | account data, content, technical data | Art. 6(1)(f) GDPR - legitimate interest of Expansio and the Employer in running internal communication; for employee data - the legal bases indicated by the Employer in its own privacy notice |
| Participation in a sports challenge: calculating points, rankings, presenting your activity | physical activity data, GPS route | Art. 6(1)(a) GDPR - your consent; to the extent this data constitutes health data - Art. 9(2)(a) GDPR (explicit consent) |
| App security: detecting abuse, unauthorised access and errors | technical data, server logs | Art. 6(1)(f) GDPR - legitimate interest in keeping the service secure |
| Handling your requests and questions (e.g. about how the app works, about your data) | contact details, content of the request | Art. 6(1)(f) GDPR - legitimate interest in supporting users; Art. 6(1)(c) GDPR - the obligation to honour data subject rights |
| Establishing, exercising or defending legal claims | data necessary for the case at hand | Art. 6(1)(f) GDPR |
| Complying with legal obligations (e.g. responding to requests from competent authorities) | data specified by law | Art. 6(1)(c) GDPR |
6. Health, physical activity and location data (Health Connect / Apple Health, GPS routes)
When this applies to you. Physical activity data and GPS routes - only if the Employer has enabled the sports challenge module in the app and you voluntarily join a challenge. If you do not take part in a challenge, the app does not read any data about your physical activity or health. Location is also used by the "Navigation" screen, if the Employer has enabled it - this is described further down in this section.
What data we read
Android (Health Connect). Only with your consent, given in the operating system's permission dialog, the app reads from Health Connect the step count and nothing else (a single permission: read steps):
- daily step totals for today and the three preceding days - points for everyday walking are calculated from them,
- step totals for the duration of activities you recorded in the app - so that the same steps are not counted twice and the competition stays fair.
From Health Connect we do not read workout sessions, distance or routes, nor any other category of health data (e.g. heart rate, sleep, weight, medical records). GPS routes come solely from recording an activity in the app itself - described further down in this section.
iOS (Apple Health). Only with your consent, the app reads from Apple Health the step count, workouts (type of activity, duration, distance) and the route of a workout, if the workout contains one. We write nothing to Apple Health. We do not read any other categories of health data.
On both systems the reading only happens while the app is open - there is no background access. The data that is read is sent over an encrypted connection (HTTPS) to our server.
Why
Solely to calculate your score in the sports challenge organised by the Employer, show you your own activity and place you in the individual or team ranking. Reading data from Health Connect / Apple Health is the equivalent of entering the result manually, just done automatically. The app also compares step sources and rejects steps that were entered manually, to keep the competition fair.
Who can see this data
You - your own results in the app. Other participants of the challenge in your company - your step count, points and ranking position, and the challenge activity wall. The challenge coordinator on the Employer's side sees participants' results in the admin panel and can export them from it. Routes and photos of activities are visible to other participants if you publish them in the activity feed.
GPS routes recorded in the app
What and when. If you start recording an activity in a sports challenge, the app reads the precise location from your phone's GPS and sends the route coordinates to our server, where they are stored together with that activity. This happens only with your consent (the system permission dialog), only while recording, and only with the app open. The app does not collect location in the background or when you are not recording an activity.
Why. Solely to calculate the distance, show the course of your workout on a map and award points in the challenge.
Who can see it. You; other participants of the challenge - if you publish the activity in the feed; the challenge coordinator on the Employer's side, in the admin panel. We do not share routes with anyone beyond the recipients listed in section 7 and we do not use them for any other purpose.
How long, and how to delete. The route is kept together with the activity, for as long as your account exists. You can delete it yourself at any time: open your activity and choose "Delete activity" ("Usuń aktywność") - the activity disappears together with the route. We also delete routes on request by e-mail and when the account is deleted (section 10).
Navigation. The "Navigation" screen, if the Employer has enabled it, uses your current position to work out a route to a given place in Google Maps. That position is used only to work out the route at that moment - we do not store it on our server. It is also processed by Google as the map provider (sections 7 and 8).
What we do not do with this data
- We do not sell your activity or health data.
- We do not use it for advertising, marketing or building profiles - neither we nor anyone on our behalf.
- We do not pass it on to data brokers, insurers, advertising networks or any other third-party companies; apart from Expansio and the Employer (the challenge coordinator), access is limited to the infrastructure providers listed in section 7.
- We do not make automated decisions with legal effects based on it. The sports ranking is the result of a simple conversion of steps and activities into points according to rules set by the Employer.
- Activity data is not used for employee evaluation or HR decisions - if the Employer has decided otherwise, it must inform you of that itself.
How long we keep it
Activity data is kept for as long as your account in the app exists - so that you can access the history of your results from successive editions of the challenge. It is not deleted automatically after any period of inactivity, nor by blocking the account alone. We delete it:
- immediately - when you delete an activity yourself in the app with the "Delete activity" button (this does not cover steps and the "streak" category),
- within 30 days of your request - when you ask by e-mail for the activity data alone to be deleted, without deleting the account (see below),
- within 30 days of a request to delete the account - together with the whole account (section 10).
Aggregated, anonymised challenge statistics (e.g. the total number of steps of the whole workforce) may be retained, but they do not allow you to be identified.
How to withdraw consent and delete the data
- Stop the reading: in the sports challenge open the "Profile" tab, choose "Import activities", and on the "Connect to other platforms" screen tap "Disconnect" next to Health Connect (on iOS: next to Apple Health) and confirm. The app then opens the Health Connect settings on your phone - revoke its permission to read steps there. On iOS you withdraw consent in: Settings → Health → Data Access & Devices → AllAbout. From that moment the app will not read any new data.
- Delete a single activity (with its GPS route): open it in the app and choose "Delete activity". It disappears at once. Steps and entries in the "streak" category cannot be deleted this way.
- Delete all the activity data collected, including steps: write to office@expansio.pl from the e-mail address linked to your account (or state your login and the name of your Employer), or report it to the challenge coordinator at your Employer. We will delete all your activity data, points and ranking positions within 30 days of the request and confirm this by e-mail.
- Delete the account together with all data: see section 10.
Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal. Uninstalling the app stops the reading of new data, but by itself does not delete data already stored on the server - for that, use the request described above.
7. Who we share data with
We do not sell personal data and we do not share it for marketing purposes. Access to data is limited to:
- Your Employer - to the extent it is the data controller, and its authorised editors and app administrators (they see content, statistics and results in the admin panel, within the roles assigned to them).
- Other app users in your company - they see what you publish yourself (comments, posts, notices with the contact details you provide, messages in channels they belong to) and your results in the sports challenge rankings, if you take part.
- Hosting provider: OVH Sp. z o.o. / OVHcloud - servers in a data centre in the European Union on which the app and its database run.
- Push notification providers: Google LLC (Firebase Cloud Messaging, Android devices) and Apple Inc. (Apple Push Notification service, iOS devices) - they receive the device token and the notification content in order to deliver it.
- Google (Google Maps) - when you use the "Navigation" screen, your current position is passed to Google as the map provider in order to work out a route; Google processes it under its own privacy policy.
- App stores (Google Play, App Store) - for downloading and updating the app, under the terms set by Google and Apple; Expansio does not receive data identifying you from them.
- Sports services you connect yourself (e.g. Garmin, Strava, Polar, Suunto) - they send us your activities only when you authorise the connection yourself; you can disconnect them in the app or in the settings of the given service.
- AI features (an assistant answering questions from the Employer's documents, message translation) - if the Employer has enabled them, the content of your question or message is processed by a language model in order to generate an answer or a translation. This content is not used to train models or for advertising purposes. The model runs on the servers of Expansio or the Employer in the European Union, unless the Employer has chosen a different configuration and informed you of it in its own privacy notice.
- Bodies authorised by law (e.g. courts, law enforcement) - only upon their lawful request.
With every entity that processes data on our behalf we conclude a data processing agreement or accept its standard data processing terms compliant with Article 28 GDPR.
8. Transfers of data outside the European Economic Area
The app, its database and backups are hosted on servers in the European Union. As a rule we do not transfer personal data to third countries.
The exception is push notifications: delivering them requires passing the device token and the notification content to the infrastructure of Google (Firebase Cloud Messaging) or Apple (APNs), which may also process data in the United States. Google LLC and Apple Inc. participate in the EU-US Data Privacy Framework (European Commission decision of 10 July 2023) and additionally apply standard contractual clauses approved by the European Commission. You can avoid this transfer by turning off push notifications. Physical activity data is not sent in notifications.
The same applies to Google Maps: when you use the "Navigation" screen, your current position is passed to Google's infrastructure in order to work out a route. You can avoid this by not using that screen, or by not granting the app the location permission. Recorded sports activity routes are stored on our servers in the European Union.
If you connect an external sports service yourself (e.g. Garmin, Strava), its provider also processes the data under the terms of its own privacy policy.
9. How long we keep data
| Type of data | Retention period |
|---|---|
| Account data and content created in the app | for as long as the account exists; deleted within 30 days of a request to delete the account (section 10). It is not deleted automatically after a period of inactivity, nor by blocking the account alone |
| Physical activity data, including GPS routes | as above; a single activity with its route can be deleted by you at once ("Delete activity"); all activity data is deleted within 30 days at your separate request, without deleting the account (section 6) |
| Notices on the notice board | visible for the period set by the Employer, after which they stop being displayed but remain on the server; deleted together with the account or at your request |
| The record that an account deletion request was carried out (account identifier and login, date) | indefinitely - solely to demonstrate accountability (Art. 5(2) GDPR); it contains no content and no activity data |
| Server logs (IP address, technical data) | no longer than 12 months, unless needed to investigate a security incident |
| Correspondence and requests sent to Expansio | for the time needed to handle the matter, then up to 3 years for the purposes of possible claims |
| Backups | data deleted from the system disappears from backups in the next backup rotation cycle; backups are used solely to restore the service after a failure and for no other purpose |
10. How to delete your account and data
There is one rule: you request account deletion by e-mail; once we have confirmed your identity we block the account without delay, and we delete the data within 30 days of the request. There is no button in the app that deletes the account. Detailed step-by-step instructions, including the full list of data you can delete yourself without deleting the account, are on a separate page: Delete your account or data.
- By e-mail (primary method): write to office@expansio.pl with the subject "Delete AllAbout account", from the e-mail address linked to your account (if you sign in with an employee number, state your login and the name of your Employer). We may ask for additional proof of identity so that we do not delete someone else's account.
- Through the Employer: submit the request to the app administrator in your company (usually the HR or communications department), who will forward it to us.
We acknowledge that the request has reached us and, once your identity is confirmed, we block the account without delay - from that moment it is no longer possible to sign in. Within 30 days of the request we delete the data linked to the account: profile data, physical activity data together with routes and points, submissions sent through forms (surveys, quizzes, pass requests, event sign-ups), files and photos, your notices, messages you sent in the employee chat, and device and sign-in tokens. We confirm the deletion by e-mail.
Exceptions - what is kept:
- Your comments stay in the app, but are no longer linked to you: the author's name changes to "Anonim" ("Anonymous"). If you want them deleted, say so in your request and we will delete them.
- Leave requests, and requests and submissions the Employer has already processed, remain in the Employer's records for the period required by labour law - this is decided by the Employer as their controller (section 2); we forward your request to the Employer and let you know.
- The record of the account deletion itself (the account identifier and login, and the date) is kept indefinitely, solely so that we can demonstrate that the request was carried out (Art. 5(2) GDPR).
- Data we are required to keep by law or to defend against legal claims (e.g. logs related to a security incident, correspondence about the request) - for the period indicated in section 9, to a limited extent. Deleted data disappears from backups in the next backup rotation cycle.
Uninstalling the app does not delete your account or the data on the server; neither does the Employer blocking your account. To have the data deleted, use one of the options described above.
11. Your rights
In connection with the processing of your data you have the right to:
- access your data and obtain a copy of it,
- rectification of inaccurate or incomplete data,
- erasure of data (the "right to be forgotten") - in the cases provided for in Article 17 GDPR,
- restriction of processing - in the cases provided for in Article 18 GDPR,
- data portability - receiving the data processed on the basis of consent in a structured, commonly used and machine-readable format,
- object to processing based on legitimate interest - on grounds relating to your particular situation,
- withdraw consent at any time - without affecting the lawfulness of processing carried out before the withdrawal,
- lodge a complaint with a supervisory authority - the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl, or the supervisory authority in your country of residence.
To exercise these rights, write to office@expansio.pl. We respond without undue delay and at the latest within one month; in particularly complex cases this period may be extended by a further two months, of which we will inform you. If your request concerns data for which the Employer is the controller, we will forward it to the Employer and let you know.
12. How we protect data
- transmission between the app and the server is encrypted (HTTPS / TLS), and data on the servers is encrypted at rest,
- passwords are stored only as cryptographic hashes,
- only authorised persons have access to data, to the extent necessary to perform their duties, and they are bound by confidentiality,
- the infrastructure is monitored for security incidents, regularly updated and subject to penetration testing,
- backups are made automatically and stored in the European Union,
- we log who changed what and when in the admin panel, for accountability purposes.
More about our practices: Security and privacy. In the event of a personal data breach likely to result in a high risk to your rights, we will inform you in accordance with Article 34 GDPR.
13. Voluntary use, no ads, no profiling
- Installing and using the app is voluntary. Not having an account only means you cannot use the app; it cannot be a basis for negative consequences on the part of the Employer.
- Taking part in a sports challenge and granting access to Health Connect / Apple Health are voluntary and independent of the use of the other features of the app.
- The app does not display advertisements, does not contain third-party ad networks and does not use data for marketing purposes.
- We do not profile users and do not make automated decisions about them that produce legal or similarly significant effects.
- The app is intended for employees and contractors of the Employer. It is not directed at children under 16 and we do not knowingly collect their data.
14. The zadbajokomunikacje.pl website
This policy also covers the zadbajokomunikacje.pl website (and its English version, allabout.mobi), of which Expansio is the controller.
- Contact forms (demo request, documentation request): the data you provide (name, company, e-mail, phone, message) is stored on the website's server and sent to office@expansio.pl so that we can answer your enquiry and arrange a presentation. Legal basis: Art. 6(1)(b) and (f) GDPR (steps prior to entering into a contract, handling enquiries). We keep the data for up to 12 months from the last contact, and if a business relationship follows - for its duration and the limitation period for claims.
- Cookies and analytics: the website does not use analytics or advertising tools and does not set tracking cookies. The only thing stored in your browser is the selected language of the website (this is not a user identifier).
- Third-party services: fonts are loaded from Google Fonts servers (Google LLC), which means your browser's IP address is passed to Google; YouTube videos load only after you click the player, from which point Google's terms apply. The hosting provider's server logs (IP address, time of request, page address) are kept by the hosting provider for the period resulting from its configuration.
15. Changes to this policy
We may update this policy when the app's features, the law or our providers change. We will inform you of material changes by a message in the app or on this page, in advance where possible. The current version is always available at zadbajokomunikacje.pl/privacy-policy.html. The date of the last update is given at the top of the document.
This information is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR). In case of discrepancies between the language versions, the Polish version prevails.
Expansio Sp. z o.o. ul. Królewska 21/8, 60-685 Poznań, Poland KRS 0000611872 · NIP 9721262893 · REGON 364151889 office@expansio.pl
AllAbout