Controller and privacy contact
MOLDEREZ-CONSULT SRL, trading as MEO safety, is the controller for the website, accounts, pet-location service, alerts, subscriptions and support. Postal address: Square Valère Gille 13/5, 1050 Ixelles, Belgium. Privacy contact and DPO: Gilles Capelluto - gilles.capelluto@molderez-consult.be.
Why pet location deserves special care
A tracker is attached to a pet, but its position can reveal a home, family routine and people’s movements. Family members who accept a private invitation can view the shared household. Only the household creator can manage profiles, pair or replace trackers and revoke family access.
MEO safety must never be used covertly to track a person, employee, vehicle or another person’s animal.
Data, purpose and retention
Account opening asks only for a first name, email address, country and language, plus the legal confirmations needed to create the account. The country is used to check MEO safety Nano-SIM availability and show when a compatible local DATA Nano-SIM is required. A short-lived one-time email code proves control of the address. Telephone, postal address, company and VAT details are not requested at onboarding. Billing details are collected later only when the account administrator asks for an invoice. Service communication uses email by default; newsletter and optional messaging remain separate and off by default.
| Data | Purpose and legal basis | Production retention |
|---|---|---|
| First name, email, country, language and OTP proof | Account, authentication and fraud prevention - contract and legitimate interest | Account lifetime; used or expired OTP challenges are deleted after 24 hours |
| Pet profile and portrait | Personalised service - contract | Until the pet or account is deleted; deletion is applied to active systems and residual protected backup copies expire through the restricted backup rotation |
| Tracker identifiers and pairing | Connectivity, inventory and tracker operation - contract and legitimate interest | While linked; pairing sessions are deleted after 1 day when terminal and after 30 days when paired |
| Location, accuracy, routes and geofences | Map, lost mode and alerts - contract | 7 days, unless a documented legal hold temporarily prevents deletion |
| Operational and security records | Reliability, abuse prevention and support - legitimate interest | Application audit records: 731 days; processed or rejected provider evidence: 180 days; terminal mail metadata: 30 days |
| Household access | Controlled sharing - contract and legitimate interest | While access remains active; related audit evidence: 731 days |
| Invoices and payment references | Payment, refunds, tax and accounting - contract and legal obligation | 10 years from 1 January following issue, in accordance with Belgian VAT retention rules |
| Newsletter | News and offers - consent | Until withdrawal; a minimal suppression record is then retained only as long as necessary to respect and demonstrate the objection |
Sharing, WhatsApp and biometric login
Invitations expire after 48 hours. Access starts only after the recipient authenticates and accepts. The household creator can revoke a member immediately, and MEO safety shows the people who belong to the shared household.
WhatsApp is optional and off by default. A precise-location answer requires verified phone ownership and To be confirmed before commercial launch. The safer default is a short-lived secure map link, not a home address in a chat.
If Face ID, Touch ID or another biometric only unlocks a passkey locally, MEO safety receives the cryptographic result, not the biometric template. If biometrics ever leave the device, Article 9 GDPR analysis and an updated DPIA are required.
Recipients and international transfers
The final notice must name the actual entities, their role, data, region, retention and transfer mechanism. Generic categories are not enough.
| Recipient or service | Purpose | Region / safeguard |
|---|---|---|
| Mollie B.V. | Payment processing | Netherlands (EU/EEA); independent payment service provider |
| OVHcloud | Application, database and storage hosting | Gravelines, France (EU/EEA) |
| 1NCE GmbH | Mobile connectivity and roaming | Germany (EU/EEA); partner networks in listed markets |
| VySkan - Unit 513, Building 4, Yusheng Comprehensive Building, No. 98 Freedom Road, 47 District, Fenshen Community, Xin’an Street, Bao’an District, Shenzhen City, China | Device supply; tracker operation, location, status and requested device actions | China; exact legal entity, DPA, SCCs, transfer-impact assessment and supplementary safeguards pending documentary review |
| WhatsApp/Meta To be confirmed before commercial launch | Optional messaging | To be confirmed before commercial launch |
Your rights, children and connected-product data
You may request access, correction, deletion, restriction, portability and objection, and withdraw consent. Direct-marketing objection is absolute. Requests: To be confirmed before commercial launch. Complaints may be filed with the Belgian Data Protection Authority.
The paying account holder must be 18+. MEO safety does not knowingly offer independent accounts or marketing to children. Any younger household mode requires a defined minimum age, parental controls and reduced permissions.
Under the EU Data Act, eligible tracker data must be described before purchase and made available in a structured, machine-readable format through a simple export or sharing flow.
Security and changes
MEO safety applies encryption in transit, per-device credentials, least privilege, privileged-user MFA, audit logs, vulnerability handling and incident response. No service can promise perfect or unbreakable security.
Material changes are notified before they take effect. A legal basis cannot be changed retroactively by merely editing this notice.
Applicable articles
Legal framework: GDPR Regulation (EU) 2016/679, Articles 5 and 6 (principles and legal bases), 12 to 14 (clear information), 15 to 22 (rights), 25 (data protection by design and by default), 32 (security) and 35 (DPIA). For tracker-generated data, Data Act Regulation (EU) 2023/2854, Articles 3 and 4, governs pre-contract information and user access.