Version: 01/10/2026
What is the purpose of our Privacy Policy?
SAS Mothair, which manages the Mothair mobile application, places great importance on the protection and confidentiality of your personal data, which represents, for us, a guarantee of seriousness and trust.
In this regard, our Personal Data Privacy Policy specifically demonstrates our commitment to ensuring that the rules applicable to personal data protection are respected within SAS Mothair, and in particular, those of the General Data Protection Regulation ("GDPR").
In particular, our Privacy Policy aims to inform you about how and why we process your personal data in the context of the services we provide to you.
Who is our Privacy Policy intended for?
Our Privacy Policy is intended for you, users of our Mothair mobile application, who hold parental authority over the children using our connected mattress.
Why do we process your personal data and on what legal basis?
We process your personal data primarily for the following reasons:
-
To use and benefit from our service and all its features, namely to allow you to monitor the health and well-being of your children by tracking their sleep, based on our Terms of Use.
-
To manage user accounts (e.g., account creation, access to the service, and account deletion) based on our Terms of Use.
-
To make online payments based on our Terms of Sale.
-
To deliver your purchases based on our Terms of Sale.
-
To receive our technical emails (e.g., password changes, etc.) based on our legitimate interest in ensuring the security of your account and providing you with the information necessary for the proper functioning of the service.
-
To allow you to download and import documents on our mobile application based on our Terms of Use.
-
To guarantee and enhance the security and quality of our services on a daily basis (e.g., statistics, data security, etc.) based on the legal obligations imposed on us, our Terms of Use, and our legitimate interest in ensuring the proper functioning of our services.
Your children's data is collected directly from them during the use of our mattress, and from you as long as you are a user of our Mothair mobile application, and we commit to processing your data only for the reasons described above.
What personal data do we process and for how long?
We have summarized below the categories of personal data and their respective retention periods:
-
Personal identification data (e.g., last name, first name, etc.) and contact details (e.g., email address) are retained for the duration of the service provision, plus the legal limitation periods, which are generally 5 years.
-
Economic and financial data (e.g., bank account number, verification code, etc.) are retained for the duration necessary for the transaction and the management of billing and payments, plus the legal limitation periods, which are generally 5 to 10 years.
-
Email address for receiving our technical messages is retained until the deletion of your account.
-
Connection data (e.g., logs, IP address, etc.) are retained for a period of 1 year.
-
Financial and asset situation is retained until the deletion of your account within the framework of the mobile application's use.
-
Health data is retained until the deletion of your account within the framework of the mobile application's use.
Upon expiration of the applicable retention periods, the deletion of your personal data is irreversible, unless a longer retention period is imposed for legal or regulatory reasons, and we will no longer be able to provide them to you after this deadline. At most, we can only retain anonymous data for statistical purposes.
Please also note that in the event of a dispute, we are obligated to retain all data concerning you for the entire duration of the case processing, even after the expiration of the retention periods described above.
What rights do you have to control the use of your personal data?
The applicable data protection regulations grant you specific rights that you can exercise at any time and free of charge to control how we use your data.
-
Right of access and copy of your personal data, provided that this request does not contradict business secrets, confidentiality, or the secrecy of correspondence.
-
Right to rectify personal data that is erroneous, obsolete, or incomplete.
-
Right to object to the processing of your personal data when it is based on our legitimate interest, unless legitimate and compelling reasons justify this processing and prevail over your interests, rights, and freedoms.
-
Right to request the erasure ("right to be forgotten") of your personal data that is not essential for the proper functioning of our services.
-
Right to restrict the processing of your personal data, which allows you to freeze the use of your data in case of a dispute regarding the legitimacy of a processing activity.
-
Right to the portability of your data, which allows you to retrieve a portion of your personal data to easily store or transfer it from one information system to another.
-
Right to give instructions regarding the fate of your data in the event of death, either through you, or through a trusted third party or a legal heir.
For a request to be taken into account, it is imperative that it be made directly by you, or your representative to dpo@mothair.fr.
Requests cannot come from anyone other than you or your representative. We may therefore ask you to provide proof of identity in case of doubt about the requester's identity, as well as justification of the representation.
We will respond to your request within the shortest possible time, with a maximum deadline of one month from receipt, unless the request is technically complex or we receive numerous requests at the same time. In this case, the response deadline may be up to three months.
Please note that we may always refuse to respond to any excessive or unfounded request, particularly if it is repetitive.
Who can access your personal data?
Your personal data is processed by our teams and by our technical providers solely for the purpose of making our service work.
We specify that we vet all our technical providers before hiring them to ensure they strictly comply with the rules applicable to personal data protection.
FURTHERMORE, WE GUARANTEE THAT WE NEVER TRANSFER OR SELL YOUR DATA TO THIRD PARTIES OR COMMERCIAL PARTNERS.
Can your personal data be transferred outside the European Union?
The personal data processed by our Mothair mobile application is exclusively hosted on servers located within the European Union.
Furthermore, we do our best to use only technical tools whose servers are also located within the European Union. If this is not the case, we strictly ensure that they implement the appropriate guarantees required to ensure the confidentiality and protection of your personal data.
How do we protect your personal data?
We implement the following technical and organizational measures to guarantee the security of your personal data on a daily basis, and in particular, to combat any risk of destruction, loss, alteration, or disclosure.
| Technical security measures | Organizational security measures | | ----- | ----- | | Password database separated from user identifiers ("Front" side), Two-factor authentication for users ("Back" side), HTTPS protocol, Access traceability, Duplication of the user database on backup servers | Information systems charter, Policy for managing permissions and passwords, Data breach management procedure, Data subject rights management procedure, Code of conduct, Team awareness and training twice a year |
Do we use cookies when you browse our mobile application?
We guarantee that we do not use any advertising or statistical cookies in the operation of our mobile application.
We only use technical cookies necessary for the proper functioning of our mobile application, which we recommend not removing and which do not require a cookie banner.
If you still wish to object to their use, you can use your browser settings by following the instructions below: Chrome, Microsoft Edge, Safari, Firefox and Opera.
Who can you contact to get more information about the use of your personal data?
To best guarantee the protection and integrity of your data, we have officially appointed an independent Data Protection Officer ("DPO") with our supervisory authority.
You can contact our DPO at any time and free of charge at dpo@mothair.fr to obtain more information or details on how we process your data.
How can you contact the CNIL?
You can contact the "National Commission on Informatics and Freedoms" or "CNIL" at any time at the following coordinates: CNIL Complaints Service, 3 place de Fontenoy – TSA 80751, 75334 Paris Cedex 07 or by phone at 01.53.73.22.22.
Can the Privacy Policy be modified?
We may modify our Privacy Policy at any time to adapt it to new legal requirements as well as to new processing activities that we may implement in the future.
Certified compliant by Dipeeo ®