top of page

GLOBAL PRIVACY POLICY

My SOS Family Ltd

Last updated 29 August 2026  |  Version 2026.4
 

The short version

​

My SOS Family is a mission-led service built to help you reach people you trust. Privacy is part of that mission. It is not something we trade for growth.


We do not sell or lease personal information. We do not give it to another organisation for its own unrelated use. We use limited information to provide, protect and improve the service, communicate with you, meet legal duties and understand whether our advertising works.


We never use SOS messages, precise location, SOS Contact details, private chat content, internet-call audio or Naya conversation content for targeted advertising.


Some specialist providers must process limited information for us. This includes providers for UK hosting, telephone calls, SMS, transactional email, marketing email, push notifications, payments, security, advertising measurement and AI. They must protect it and use it only for the agreed purpose, unless a platform acts independently under its own privacy terms.


Private chat messages are encrypted while being sent and are removed from our central delivery service after delivery. Copies remain on the participating devices until the user deletes them, removes the app or chooses to save or export them.


You can manage or delete most information in the app or through our website account controls. You can also contact our Privacy Officer. Limited records may remain where needed for security, opt-outs, tax, legal claims or protected backups.

​​

1. Our privacy promise

​​

We want My SOS Family to do good and cause no avoidable harm. We collect the least information we reasonably need and use it in ways that respect the person behind it. Care does not stop because someone is upset, confused or difficult to help.


1.    We do not sell or lease personal information.
2.    We do not allow investors, shareholders, lenders, resellers or partners to use personal information merely because they fund, own, promote or work with us.
3.    A change in ownership does not by itself create a new lawful purpose for personal information.
4.    We do not use safety information or private communications as an advertising asset.
5.    We do not design Naya or the wider service to encourage compulsive use. There are no streaks, no messages saying 'I missed you', and no pressure or return nudges designed to create dependence.
6.    If we make a material change, we will explain it clearly. We will obtain fresh consent where the law requires it.

​

No privacy policy can prevent every future corporate event. Any successor must handle personal information consistently with the policy and law that apply at the time. It cannot lawfully treat a purchase or investment as permission for an unrelated new use.


2. Who we are

​​

My SOS Family Ltd is responsible for the processing described in this policy unless section 22 explains a different role for an organisation or reseller account.

7.    Company number 08918454
8.    Registered office 20-22 Wenlock Road, London, N1 7GU, England
9.    Privacy correspondence 22 Heron Court, Bromley, Kent, BR2 9LR, United Kingdom
10.    UK Information Commissioner's Office registration ZA097950
11.    Privacy Officer email privacy@mysosfamily.com
12.    Alternative monitored contact info@mysosfamily.com
The Privacy Officer is also the contact for Canada and Quebec. The person with the highest authority in the company holds this responsibility unless it has been formally delegated.

​

3. What this policy covers

​

This is the main privacy policy for the services operated by My SOS Family Ltd. It covers:


13.    the public My SOS Family website and web account pages
14.    the iPhone and iPad app distributed through Apple
15.    the Android app distributed through Google Play and supported Amazon devices
16.    the My SOS Family Alexa skill and account linking
17.    our UK-hosted account, contact and safety-service backend
18.    SOS, SOS Timer, Check-in, landline, telephone, SMS, email and app-notification features
19.    private one-to-one and group chat
20.    static and live location sharing
21.    secure worldwide internet calling where available
22.    Naya, the everyday-conversation AI companion inside supported versions of the app
23.    subscriptions, vouchers, support, organisations, resellers and integrated hardware
24.    analytics, advertising and campaign measurement used to promote My SOS Family

​

Apple App Privacy information, Google Play Data safety information, Alexa notices and permission prompts are shorter notices. They must match this policy and the live service. A local notice or consent screen may add detail for a particular feature or country.

​​

4. The information we collect

​​​

What we collect depends on the features you choose. We may process the following categories.

​​

Category - Account details:
Examples and source  First name, surname, mobile number, email address, country, language, account settings and authentication information supplied by you.

 

Category - SOS Contact details
Examples and source  Name, telephone number, email address, relationship and selected alert channels for people you choose. These details normally come from you.

 

Category - Subscription details
Examples and source  Plan, trial, voucher, entitlement, purchase, renewal and cancellation status received from an app store or payment provider. We do not store a full card number.

 

Category - Device and service data
Examples and source  Device type, operating system, app version, language, push token, limited service identifiers, permissions, security data, crash or diagnostic information.

 

Category - Location
Examples and source  Static or live location supplied by your device when you start an SOS, Timer, Check-in or location-sharing feature and allow the permission.

 

Category - Safety events
Examples and source  Alert type, date, time, selected contacts, provider submission, delivery result, response status and limited evidence needed to operate or investigate the event.

 

Category - Chat
Examples and source  Private message content while it waits for delivery, delivery metadata and local copies held on participating devices.

 

Category - Internet calling
Examples and source  Participants, date, time, connection status and limited security or diagnostic data. We do not record or keep call audio.

 

Category - Naya
Examples and source  What you type, limited conversation context, optional memory, usage allowance and limited feature activity needed to provide Naya.

 

Category - Support
Examples and source  Messages, attachments and contact details you provide when asking for help, making a complaint or exercising a privacy right.

 

Category - Website and advertising
Examples and source  Pages viewed, browser and device data, approximate location from IP, cookie choices, campaign source, ad interaction, conversion and similar online identifiers.

 

Category - Alexa
Examples and source  The interpreted command, linked-account identifier and service event needed to carry it out. Amazon processes the audio and does not give the recording to us.

​
5. Where the information comes from

​​

25.    directly from you when you register, choose features, contact support or communicate with Naya
26.    from your device when you grant a permission or use a feature
27.    from the person who adds you as an SOS Contact, check-in contact or organisation user
28.    from your app store, payment provider or voucher administrator
29.    from telecommunications, email, push and internet-call systems when they report submission, delivery, failure or response information
30.    from Apple, Google, Amazon, Meta and other advertising or analytics services when they provide campaign and attribution information
31.    from an employer, membership organisation, reseller or hardware partner where it lawfully arranges the service for you

​

6. Why we use personal information

​​

  • Purpose -  Provide the service

What it supports:  Account, authentication, SOS, Timer, Check-in, chat, calling, location and chosen features.
UK and EEA basis where applicable:  Contract

​

  • Purpose - Reach chosen people

What it supports:  Calls, SMS, email and app notifications to SOS Contacts and their replies.
UK and EEA basis where applicable:  Contract. Vital interests may apply to a genuine urgent threat.

​

  • Purpose - Provide Naya

What it supports:  Generate everyday-conversation replies, apply user choices, maintain optional memory and show user-enabled safety warnings.
UK and EEA basis where applicable:  Contract and consent where required.

​

  • Purpose - Take and verify payment

What it supports:  Subscriptions, vouchers, receipts, entitlements, refunds and fraud controls.
UK and EEA basis where applicable:  Contract and legal obligation

​

  • Purpose - Protect the service

What it supports:  Security, authentication, abuse prevention, fault finding, delivery investigation and resilience.
UK and EEA basis where applicable:  Legitimate interests, recognised legitimate interests and legal obligation

​

  • Purpose - Support users

What it supports:  Answer questions, resolve problems, handle complaints and privacy requests.
UK and EEA basis where applicable:  Contract, legitimate interests and legal obligation

​

  • Purpose - Improve the service

What it supports:  Understand reliability, accessibility and feature use using the minimum data needed.
UK and EEA basis where applicable:  Legitimate interests or consent where required

​

  • Purpose - Market My SOS Family

What it supports:  Optional marketing email and lawful campaign measurement.
UK and EEA basis where applicable:  Consent or another lawful basis permitted for that communication

​

  • Purpose - Advertising

What it supports:  Promote the service and measure public website or app-install campaigns.
UK and EEA basis where applicable:  Consent where required. Opt-out rights apply in some US states.

​

  • Purpose - Meet legal duties

What it supports:  Tax, accounting, safeguarding, disputes, court orders, regulators and lawful requests.
UK and EEA basis where applicable:  Legal obligation, legitimate interests or another lawful condition


Where we rely on legitimate interests, we consider necessity, proportionality and the person's reasonable expectations. You can object where the law gives you that right. Vital interests is not used as a routine substitute for consent.

​

7. SOS Contacts and other people whose details you add

​

When a user gives us an SOS Contact's details, we have obtained the information from the user rather than directly from the contact. We use it only to set up and deliver the contact role, provide related service information, manage replies and opt-outs, and meet legal duties.


32.    The user must have the person's express permission before adding them.
33.    Where the service offers a direct invitation or confirmation, the contact must confirm before the relevant route becomes active.
34.    We do not add SOS Contacts to unrelated marketing lists.
35.    A contact can reply STOP where supported, use another removal route in the message, ask the user to remove them or contact us directly.
36.    We keep a limited suppression record where needed so an opt-out is not accidentally reversed.
37.    A contact can ask what we hold, correct it or request deletion, subject to lawful exceptions.

 

8. Calls, SMS, emails and app notifications

​

We use contracted communications providers to send alerts and service messages. Different providers may handle telephone calls, SMS, transactional email, marketing email and app notifications. We describe them by service category because publishing our supplier and routing map could create security and commercial risk.


A provider receives only what it needs for the communication. This may include the destination, sender information, message or voice content, language, event identifier, timing, delivery status and opt-out instruction. Communications may pass through carriers and networks in the countries where the user and contact are located.


Transactional and alert messages are kept separate from marketing. We do not put advertising into an SOS alert, contact invitation or opt-out confirmation. Marketing messages include the controls required by the country and can be stopped at any time.


9. Private chat

​

Private by design

​

Chat messages are encrypted while being sent. Our central delivery service keeps a message only while needed to deliver it. Once receipt is confirmed, the central delivery copy is removed.
The sender and recipient may keep local copies on their own devices. A user can delete local messages, remove the app, or use an available export or backup setting to save a copy to a personal device or cloud account. Those personal copies are controlled by the user and the chosen cloud provider.


We do not routinely read or monitor private chat content. We may receive content if a user deliberately sends it to support or reports abuse before it has disappeared from their device. Limited metadata may remain for security, delivery and legal purposes.

​

Deleting the app normally removes app data from that device, but it cannot delete a copy kept by another participant or a copy the user exported or backed up elsewhere.


10. Location

​

We do not run continuous family tracking as the default service. Location is used when you start a feature that needs it and allow the relevant device permission. You remain in control of static or live sharing.

 

38.    Location may be attached to an SOS, SOS Timer, Check-in or deliberate live-location session.
39.    If an active feature continues in the background, location may continue for that feature and the app will use the device indicators and controls required by the platform.
40.    The current service location may be replaced when a later SOS or location event occurs. Limited event, delivery, security or dispute records may remain under our retention schedule.
41.    You can stop an active live-sharing session in the app and change permission in the device settings.
42.    We do not use precise location for targeted advertising or sell it.

​

11. Secure internet calling

​

Where secure worldwide internet calling is available, we use specialist connection services to connect authorised participants. Audio is encrypted while being sent. We do not record the call or store the audio.

 

We may process the participants, date, time, connection state, network information and limited security or diagnostic data needed to set up, protect and troubleshoot the call. We do not publish the connection design, network topology or security configuration because that information is not needed to understand the privacy effect and could weaken security.

​

12. Naya

​

12.1 What Naya is and is not


Naya is an AI companion for ordinary, everyday conversation. It is not designed, offered or intended as a health, medical, mental-health, clinical, therapy, counselling, wellbeing, diagnostic, treatment, crisis or emergency service. My SOS Family is not a healthcare provider and does not provide healthcare through Naya or any other feature.


Naya does not diagnose, assess or monitor a person's health, recommend treatment, manage medication, maintain a medical record or determine whether someone has a physical or mental-health condition. It can make mistakes and must not be relied on for professional advice or urgent help. A person needing medical, mental-health, crisis or emergency support must use an appropriate qualified service.

​

12.2 Ordinary conversation content

​

We do not ask users to provide medical records, diagnoses, symptoms, medication details or other health information to Naya. Naya should not be used to seek health or medical advice. As with an email, SMS or private message, a user may nevertheless choose to mention personal matters in ordinary conversation. We process that content only to provide the conversation the user requested.

 

We do not use it to create a health profile, identify a health condition, provide care, determine eligibility, set a price or target advertising.

 

12.3 Third-party AI processing

​

To generate a reply, what you type and limited context needed for the conversation are securely sent to a contracted AI provider in the United States. We disclose this before first use and obtain the permission required by Apple, Google and applicable law.


43.    My SOS Family does not train its own AI models on Naya conversations.
44.    Our contracted AI provider is not permitted to use Naya content to train general-purpose models.
45.    We do not deliberately attach ordinary account identifiers such as your name, telephone number or email address to the content sent for a reply.
46.    You may still type personal information into a conversation. Avoid including information that is not needed.
47.    Naya conversation content is not used for advertising.

 

12.4 Conversation context, memory and deletion

​

My SOS Family does not keep a permanent account transcript of Naya conversations. Limited context may be processed temporarily so the conversation makes sense. If optional memory is available, you can view and delete the saved memory in Naya. Switching memory off means a later conversation starts without that saved memory.


A contracted provider may retain limited information temporarily for service security and abuse prevention under its contract with us. The provider's actual retention and deletion settings must remain aligned with our store disclosures and internal processor records.


12.5 Optional safety warning

​

Naya may recognise language that appears to describe an immediate danger, threat or risk of violence solely so it can show general safety information or start a user-enabled warning and countdown before an ordinary SOS. This is a safety routing function. It is not a health assessment, diagnosis, clinical judgement or emergency-monitoring service. It does not create a health profile. The user can cancel the warning and can switch the feature off. Naya conversation content is not sent to SOS Contacts.


A minimal service record may be kept where a warning or SOS event occurs, such as the date, event type and whether an SOS was started or sent. We do not need to keep the conversation itself for that record. The warning does not make a decision that determines a person's legal rights, access to a service, price, employment, insurance or healthcare.


12.6 Non-addictive design

​

Naya is not designed to create emotional dependence. We do not use streaks, 'I missed you' messages, guilt, false claims of need, or notifications designed to pressure you to return. Free daily interactions may be limited. A paid in-app purchase may allow more use, but the limit and purchase prompt are not designed as an emotional hook.


13. Apple devices and the App Store

​

Apple processes App Store accounts, purchases, receipts, device permissions, Apple advertising attribution and related platform information under Apple's own privacy terms. We receive the limited purchase, entitlement, attribution or technical information needed to operate and measure our app. We do not receive a full payment-card number from Apple.


The app asks for permissions such as notifications, contacts, location or calling only where a feature needs them. You can refuse or change a permission in iOS or iPadOS settings. If any feature tracks activity across other companies' apps or websites, it will use Apple's App Tracking Transparency permission before that tracking occurs. Privacy-preserving Apple advertising attribution may be used to measure Apple Ads campaigns.


Before personal information is sent to a third-party AI provider, the app provides a clear disclosure and obtains explicit permission as required by Apple's current rules. The Privacy Policy link must remain available in the App Store listing and inside the app.


14. Google Play and Android

​

Google processes Google Play accounts, purchases, subscriptions, device services, advertising attribution and related platform information under Google's own privacy terms. We receive limited entitlement, receipt, attribution, push and technical information needed for the service. We do not receive a full payment-card number from Google.


Android permissions are requested when needed for a feature. Prominent disclosure and affirmative consent are used before sensitive or unexpected collection where required, including any active background-location use. The public Google Play Data safety declaration must match the app, its permissions and its third-party software.


Users can delete their account through the app and through the web account-deletion route linked from Google Play. Deleting an account does not automatically cancel a Google Play subscription. Google controls that separate subscription process.


15. Alexa and supported Amazon devices

​

Amazon listens for the wake word, processes speech and interprets an Alexa request under the privacy settings and terms for the user's Amazon account. My SOS Family receives the interpreted request and account-linking information needed to carry it out. We do not receive or store the Alexa audio recording.


48.    Account linking exchanges limited identifiers and tokens. Amazon does not receive your My SOS Family password.
49.    You can unlink the skill in Alexa. Unlinking stops future access through that linked account.
50.    A voice command can create the same limited safety event record as the matching app action.
51.    Anyone able to speak to the Alexa device may be able to trigger a supported command.
52.    The Alexa skill does not itself contact public emergency services.

​

This policy and the Terms must be available for every live Alexa locale. Properly localised versions must be used for French, German, Spanish and any other language in which the skill is offered.


16. Website, cookies and similar technology

​

The public website uses essential technology needed for security, page delivery, forms and account access. It may also use analytics and advertising cookies, pixels or similar technology. Our Cookie Policy provides the current list and controls.

 

Where consent is required, non-essential technology is not used until you choose to allow it. You can change your choice through the cookie or Privacy Choices control. A choice may need to be made again if cookies are cleared, the browser changes or the law requires a renewed choice.

 

17. Advertising, analytics and campaign measurement

​

We advertise My SOS Family through Apple Ads, Google Ads, Meta advertising, Amazon Ads and other advertising services. We may use campaign links, app-store attribution, website pixels, cookies and conversion measurement to understand whether an advert led to a visit, install or purchase.


Depending on the platform and your choices, advertising providers may receive online identifiers, IP address, browser or device information, cookie choice, advert and campaign identifiers, page or app-install events and limited conversion information. They process some information under their own privacy terms.

​

Safety data is kept out of advertising

​

We do not send SOS content, precise location, SOS Contact details, private chat content, internet-call audio or Naya conversation content to advertising platforms for targeted advertising.

​

We do not upload SOS Contact lists for advertising. We do not use a person's safety event to decide which advert they should see.

​

We do not sell personal information for money. Some US state laws use the words 'sale', 'sharing' or 'targeted advertising' broadly. A consented disclosure of website identifiers to an advertising platform may fall within those definitions even where no money is paid for the information. Where that applies, we provide an opt-out, honour qualifying browser preference signals and do not discriminate for using the right.

 

18. Marketing and service communications

​

Service messages explain account activity, security, setup, alerts, payments or changes needed to use My SOS Family. Marketing messages promote the service. We keep these purposes separate.


53.    Marketing email is sent only where we have consent or another lawful basis permitted in that country.
54.    Every marketing email provides the required way to opt out.
55.    Opting out of marketing does not stop essential service, security, billing or SOS communications.
56.    SOS Contacts are not used for unrelated marketing merely because another user added them.
57.    We may keep a limited suppression record so we continue to respect an opt-out.

​

19. Who receives personal information

​

  • Recipient category - People you choose

Why information may be provided:  SOS Contacts, check-in contacts, chat participants or others you deliberately share with.

​

  • Recipient category - Communications providers

Why information may be provided:  Telephone calls, SMS, transactional email, marketing email and related delivery or opt-out services.

​

  • Recipient category - UK hosting and security providers

Why information may be provided:  Core account, contact and service hosting, databases, protected backups, monitoring, authentication and recovery.

 

  • Recipient category - Device and push platforms

Why information may be provided:  App notifications, permissions, device services and technical support for Apple, Google and Amazon environments.

 

  • Recipient category - Secure internet-call providers

Why information may be provided:  Connecting and protecting calls without recording or retaining call audio.

​

  • Recipient category - AI provider in the United States

Why information may be provided:  Generating Naya responses and supporting user-enabled safety warnings after the required disclosure and permission.

 

  • Recipient category - Payment and app-store providers

Why information may be provided:  Purchases, receipts, subscription status, vouchers, entitlement and fraud prevention.

​

  • Recipient category - Analytics and advertising providers

Why information may be provided:  Consented website analytics, campaign attribution, app-install measurement and advertising described in section 17.

 

  • Recipient category - Support and business communications providers

Why information may be provided:  Handling support, privacy requests and company communications.

​

  • Recipient category - Organisations and resellers

Why information may be provided:  Setting up and administering an account where the person is enrolled through that organisation or reseller.

 

  • Recipient category - Professional advisers and authorities

Why information may be provided:  Legal, audit, insurance, tax, regulatory, safeguarding and lawful disclosure requirements.

​

  • Recipient category - A genuine successor

Why information may be provided:  A lawful merger, restructuring or transfer, subject to this policy, due diligence safeguards, notice and any required consent.


We maintain a detailed internal processor register, contracts, transfer records and security assessments. We do not publish supplier names, routing details or infrastructure maps unless the law requires more detail. Where you have a legal right to receive specific information, we provide what that law requires.


20. International processing

​

Core account, contact and safety-service data is hosted in the United Kingdom. Specialist providers and support arrangements may process limited information in the United Kingdom, the European Economic Area, the United States, Canada, Australia, India and Colombia. Communications may also pass through carriers and networks in the country where a user or SOS Contact is located.


When a transfer needs a safeguard, we use the mechanism required by the relevant law. This may include an adequacy regulation or decision, the UK International Data Transfer Agreement or UK Addendum, EU Standard Contractual Clauses, the EU-US Data Privacy Framework and UK Extension where valid, contractual protections, a privacy impact or transfer assessment, or another recognised mechanism.


For Australia, we remain accountable where the Privacy Act and Australian Privacy Principles require it.

​

For Canada and Quebec, we remain accountable for information sent to a provider for processing and complete the assessments required for qualifying transfers.

​

For Colombia and India, we apply the consent, notice, contract, transfer and grievance requirements that are in force and apply to the processing.

​

21. How long we keep information

​

We use a documented retention schedule. We keep information only as long as reasonably needed for the purpose, user choices, safety, security, opt-outs, tax, disputes and legal requirements.

​

  • Information - Account and profile

Retention approach:  While active, then for the limited closure, security, dispute or legal period before deletion or anonymisation.

​

  • Information - SOS Contact details

Retention approach:  While the contact remains active, with a limited suppression record retained where needed to honour an opt-out.

​

  • Information - SOS, Timer and Check-in events

Retention approach:  Only as long as needed to operate and evidence the service, investigate delivery or safety, handle complaints or legal claims, then deleted or anonymised.

​

  • Information - Chat delivery copy

Retention approach:  Until delivered or the delivery attempt expires. Removed from the central delivery service after confirmed receipt.

​

  • Information - Chat on a device

Retention approach:  Until a participant deletes it, removes the app or manages an exported or cloud copy.

​

  • Information - Location

Retention approach:  For the active feature and limited related event, delivery, security or dispute period. A later location may replace the current service location.

​

  • Information  Internet-call audio

Retention approach:  Not recorded or retained by My SOS Family.

​

  • Information - Naya conversation

Retention approach:  No permanent My SOS Family account transcript. Temporary provider processing is limited by contract.

​

  • Information - Naya memory

Retention approach:  Until the user deletes it, switches off the relevant memory or closes the account, subject to limited lawful exceptions.

​

  • Information - Naya feature event

Retention approach:  Only a minimal service record of a warning or SOS event, and only for the documented safety, legal or dispute period.

​

  • Information - Billing and tax

Retention approach:  For the period required by tax, accounting, fraud and payment-dispute law. This is commonly six years for relevant UK records.

​

  • Information - Support and privacy requests

Retention approach:  For as long as needed to resolve and evidence the matter and meet a related legal or regulatory period.

​

  • Information - Marketing choice

Retention approach:  Until changed, with a limited suppression record retained so the choice is respected.

​

  • Information - Backups

Retention approach:  Deleted information is removed or overwritten through the protected backup cycle and is not restored to ordinary active use.


22. Organisations, resellers and hardware partners

​

An employer, membership body, public service, reseller or hardware partner may arrange My SOS Family for a person. Privacy roles depend on the arrangement. The organisation may control some enrolment or administration information, while My SOS Family controls processing needed for its own service, security, legal and user-support purposes. A written agreement must describe the roles.


Resellers and partners must treat users with the same care, dignity and respect that My SOS Family expects for its own family. They may use personal information only for the agreed service and lawful administration. They must not use it for unrelated marketing, sell it, bypass an opt-out or give it to another party without a lawful basis and the required notice.


Where integrated hardware initiates an alert, the service may receive the device identifier, user link, command, time, location if enabled, status and diagnostic information needed to carry out and investigate the event. We do not publish integration credentials or technical design.

 

23. Security

​

We use technical and organisational safeguards designed for the sensitivity and risk of the information. These include encryption in transit, appropriate encryption at rest, access controls, authentication, separation of duties, monitoring, backups, supplier checks, testing, incident response and staff confidentiality.


No internet service is risk-free. We do not publish detailed network, security, supplier or recovery information that could make the service easier to attack. If a personal data breach occurs, we assess it, contain it and notify regulators and affected people where the applicable law requires it.


24. Your controls and deletion

​

58.    Edit account and SOS Contact details in the app or web account where the control is available.
59.    Remove SOS Contacts and stop a live-location session.
60.    Delete local chat messages or remove the app from the device.
61.    View or delete Naya memory and switch off optional Naya memory or safety-warning settings where available.
62.    Change device permissions through Apple, Android or Amazon settings.
63.    Change cookies and advertising choices through the website controls.
64.    Unsubscribe from marketing messages.
65.    Request account deletion in the app or through the website account-deletion route.
66.    Contact the Privacy Officer for access, correction, deletion, objection, restriction, portability, consent withdrawal or another applicable right.

​

Account deletion and subscription cancellation are separate. Deleting the My SOS Family account does not cancel an Apple, Google, Amazon or other independently managed subscription. The relevant subscription must be cancelled through its payment platform.

 

25. Your privacy rights

​

Rights vary by location. Where the relevant law applies, you can ask us to:


67.    confirm whether we process personal information and give you access
68.    correct inaccurate or incomplete information
69.    delete information, subject to lawful exceptions
70.    restrict or object to certain processing
71.    provide a portable copy where the right applies
72.    withdraw consent for future processing
73.    stop direct marketing
74.    opt out of sale, sharing, targeted advertising or qualifying profiling
75.    limit or withdraw consent for certain uses of sensitive information
76.    provide information, human intervention and a way to contest a qualifying automated decision
77.    appeal a refused request where local law provides that right
78.    make a complaint to us and to the regulator that applies where you live

​

Email info@mysosfamily.com. We may verify identity and authority before acting. We respond within the period required by the law that applies. We do not discriminate against someone for using a privacy right.

 

26. Regional information

​

26.1 United Kingdom


We apply the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations and the Data (Use and Access) Act 2025 where they apply. We identify an Article 6 basis and, for special-category information, a separate Article 9 condition.


A UK privacy complaint can be made electronically. We acknowledge it within 30 days, investigate it without undue delay, keep the person appropriately informed and explain the outcome. A person may also complain to the Information Commissioner's Office.


UK regulator  Information Commissioner's Office

 

26.2 European Economic Area, France, Germany and Spain

​

Where the EU GDPR applies, users have the rights described in section 25 and may complain to the supervisory authority in their EEA country. We provide Article 13 information when collecting directly and Article 14 information where SOS Contact or organisation details come from someone else, subject to lawful exceptions.


We use local-language notices and consent wording where required. French, German and Spanish versions must stay aligned with this English policy and the features offered in that market. International transfers use an applicable adequacy decision, Standard Contractual Clauses and supplementary measures, or another lawful route.


26.3 United States

​

US privacy rights differ by state and often depend on business size, activity and thresholds. Where an applicable state law gives a right, we honour it. We may choose to honour the same request more broadly even where a statutory threshold is not met.


79.    Rights may include access, confirmation, correction, deletion and portability.
80.    Rights may include opting out of sale, targeted advertising, cross-context behavioural advertising or qualifying profiling.
81.    Sensitive information is used only for the service, safety, security and other disclosed purposes. Consent is obtained where the applicable state law requires it.
82.    We recognise qualifying universal opt-out signals, including Global Privacy Control, where required.
83.    An authorised agent may submit a request where the law allows it and the authority can be verified.
84.    A person may appeal a refusal where state law provides that right.

 

26.4 California Notice at Collection

​

This section describes categories of personal information that may have been collected during the preceding 12 months. We do not collect every example listed in a legal category merely because California law places it in that category.

​

 

  • California category - Identifiers and customer records

My SOS Family examples:  Name, telephone, email, account ID, SOS Contact details.
Purpose and disclosure:  Account, alerts, support, security and communications. Service-provider disclosure.
Sale or sharing:  Not sold. Contact details are not used for targeted advertising.

​

  • California category - Commercial information

My SOS Family examples:  Plan, trial, voucher, purchase and entitlement status.
Purpose and disclosure:  Subscriptions, accounting, support and fraud prevention.
Sale or sharing:  Not sold.

 

  • California category - Internet, device and app activity

My SOS Family examples:  Browser, device, app, diagnostics, pages, ad and campaign events.
Purpose and disclosure:  Service, security, analytics and consented advertising.
Sale or sharing:  Website or attribution activity may be sharing. Opt-out available where required.

​

  • California category - Geolocation

My SOS Family examples:  Approximate website location and precise feature location.
Purpose and disclosure:  SOS, Timer, Check-in, live sharing and localisation.
Sale or sharing:  Not sold or used for targeted advertising.

​

  • California category - Sensitive personal information

My SOS Family examples:  Credentials, precise location and private communication content.
Purpose and disclosure:  Authentication, safety, chosen features and user-directed communications.
Sale or sharing:  Not sold. Used only for disclosed service and permitted purposes.

​

  • California category - Inferences

My SOS Family examples:  Limited campaign and advertising attribution.
Purpose and disclosure:  Advertising measurement and service improvement.
Sale or sharing:  Website or attribution activity may be sharing. Opt-out available where required.


Sources are described in section 5.

Purposes are in sections 6 to 18.

Recipient categories are in section 19.

Retention criteria are in section 21.

 

We do not offer a financial incentive in exchange for personal information. We do not knowingly sell or share the personal information of people under 16.


Use the Privacy Choices control to opt out where our website advertising falls within California sale or sharing. We honour qualifying opt-out preference signals. We use sensitive personal information only for disclosed service, safety, security and other legally permitted purposes, so a separate limitation control may not apply. If that use changes, we will provide the required control.

​

26.5 Not a health or medical service

​

My SOS Family is a personal safety and communication service. It is not a health, medical, mental-health, clinical, therapy, counselling, wellbeing, diagnostic, treatment, crisis or healthcare service. We do not ask for medical records, diagnose or monitor health, provide treatment, manage medication, determine health status or create health profiles.


A user may choose to include personal information in an SOS message, private chat, support request or Naya conversation, just as they may in an email or SMS. We process that user-directed content only to provide the communication or feature requested. We do not use it to infer or identify a health condition, provide healthcare, make a health-related decision, advertise to the person or build a health-data product.


Some laws protect particular information regardless of the type of company receiving it. If a law applies to particular content despite the limited purpose described above, we will apply the rights, consent, security and deletion duties required for that content. This does not change the nature or intended purpose of My SOS Family or Naya.


26.6 Canada and Quebec

​

We apply PIPEDA and applicable provincial private-sector laws where they apply. We remain accountable for personal information transferred to a service provider for processing and use contracts or other safeguards to provide comparable protection.


For Quebec, the Privacy Officer contact is in section 2. We carry out the required privacy impact assessments for qualifying technology projects and transfers outside Quebec. We provide information about technology that identifies, locates or profiles, and optional functions are off by default where the law requires activation by the user.


Where a qualifying decision is made exclusively by automated processing, we provide the information, observations and human contact required by Quebec law. Quebec users may exercise access, correction, deletion where applicable, consent withdrawal, portability and complaint rights.
Federal regulator  Office of the Privacy Commissioner of Canada
Quebec regulator  Commission d'acces a l'information

​

26.7 Australia

​

Where the Privacy Act and Australian Privacy Principles apply, this policy is our APP Privacy Policy. Australians can ask for access or correction and complain to us. We investigate and explain the response. If a person remains dissatisfied, they may contact the Office of the Australian Information Commissioner.


Likely overseas processing countries are listed in section 20. We take reasonable steps before overseas disclosure and remain accountable where APP 8 and section 16C require it. We do not rely on a blanket statement that privacy protection ends when information leaves Australia.
Australian regulator  Office of the Australian Information Commissioner


26.8 India

​

We apply the Digital Personal Data Protection Act 2023 and Digital Personal Data Protection Rules 2025 as their provisions come into force and apply to the service. We provide clear notice, seek valid consent where required, collect only what is necessary for the stated purpose and provide a way to withdraw consent that is as easy as giving it.


An Indian Data Principal may use the rights that are in force and applicable, including access to information, correction, completion, updating, erasure, grievance handling and nomination. A grievance can be sent to the Privacy Officer before using any statutory escalation route. We also respect applicable telecommunications consent, sender-registration and Do Not Disturb controls for communications.

 

26.9 Colombia

​

Where Colombian data-protection law applies, processing is carried out under Law 1581 of 2012 and its implementing rules as amended. The person may know, access, update and correct personal information, ask for proof of authorisation, be told how it has been used, revoke authorisation or request deletion where the law allows, and complain to the Superintendencia de Industria y Comercio after completing the required direct procedure.


Sensitive information is optional unless a chosen feature clearly requires it. We explain that a person is not obliged to provide sensitive information and obtain the required express consent. International transfer or transmission uses the authorisation, contract and legal safeguards required by Colombian law.


Colombian regulator  Superintendencia de Industria y Comercio

 

26.10 Other countries

​

If a local privacy law gives stronger or additional rights, the local law prevails for that person. We may provide a local notice, consent screen, language version, representative or request route. A feature may be limited where the required privacy, communications or provider arrangements are not available.


27. Children

​

The service is not directed to children acting independently. A base My SOS Family account for a person under 18 must be created and supervised by a parent or guardian in accordance with the service and law for that country. Naya is for users aged 18 or over.


We do not knowingly sell or share a child's personal information for targeted advertising. If we learn that information was collected from a child without the required authority, we take appropriate steps, including deletion where required.


28. Changes to this policy

​

We may update this policy when the service, providers, law or processing changes. We update the date and version at the top. For a material change, we provide additional notice and obtain fresh consent where the law requires it. We keep the version accepted or shown to users as part of our release records.


29. Contact and complaints

​

For privacy questions, requests or complaints, email privacy@mysosfamily.com or info@mysosfamily.com. Write to Privacy Officer, My SOS Family Ltd, 22 Heron Court, Bromley, Kent, BR2 9LR, United Kingdom.
Please explain what you need and the country or state where you live. We may ask for enough information to confirm identity and protect the account. If you are not satisfied, you can complain to the privacy regulator that applies where you live.
 

bottom of page