PART A โ General Section (applies to all users worldwide)
Welcome to the Heartbeat Pakistan Privacy Policy. This Policy explains which personal data we collect from you when you use our platform and the associated services, applications and content (together, the "Services"), as well as how we use, process and protect your personal data.
Heartbeat Pakistan is operated by Schwaben Apps, Augsburg. We are the controller for the processing of your personal data within the meaning of the GDPR. By using our Services, you consent to the collection, processing and use of your data in accordance with this Privacy Policy. If you do not agree with this Policy, you may not use our Services.
We use the General Data Protection Regulation (GDPR) of the European Union as the core standard for the protection of your data โ regardless of where you are located. In Part B you will find additional information that applies specifically to your country or region.
ยง 1 โ WHO WE ARE
Controller within the meaning of data protection law:
Operator: Schwaben Apps
App name: Heartbeat Pakistan
Email: support@heartbeatpakistan.com
Contact details and the full legal notice (imprint) can be found at: https://heartbeatpakistan.com
Heartbeat Pakistan is a social media platform in the form of a native mobile app for iOS and Android. We offer our Services worldwide and support 29 languages.
ยง 2 โ WHICH DATA WE COLLECT
a. Data that you provide to us upon registration:
- Email address โ for login, email verification and account recovery
- Password โ stored as a cryptographic hash (the plain-text password is never stored)
- Display name โ your publicly visible name
- Date of birth โ for age verification (minimum age: 18 years)
- Consent date โ the time of your consent to the Terms of Service and the Privacy Policy
b. Data that you voluntarily add to your profile:
- Username (e.g. @example)
- Profile picture and banner image
- Bio text (a description about you)
- Profile card (an optional profile card with personal details)
- Phone number (optional, for additional verification)
c. Content that you create:
- Posts โ text, photos, videos (stored with Cloudflare R2)
- Triple Posts โ posts that are published simultaneously as a feed post, viral video and challenge post
- Viral videos โ short videos in full-screen format
- Stories โ content that is automatically deleted after 24 hours
- Polls โ polls with up to four answer options, color scheme selection and an optional expiry date
- Comments โ reactions to other users' posts
- Chat messages โ text, voice and media messages (stored in Firebase Firestore, transmitted via TLS)
- Voice messages โ audio recordings in chat
- GIFs and stickers โ selected via Giphy and sticker services
- Live streams โ real-time video broadcasts
- Community audio rooms โ audio group rooms (recordings possible)
- Drafts โ post drafts stored locally and on the server
- Sale & Purchase (classified listings) โ title, description, price, currency, category, location, images, publication status, coin transactions for publishing, and saved favorites
d. Social interactions:
- Friends list โ the user IDs of your friends
- Friend requests โ sent and received
- Likes โ on posts, virals and comments
- Followers/following โ for public profiles
- Mentions (@mentions)
- Challenge participations
- Poll votes โ the answer you selected in other users' polls
- Gifts โ virtual gifts sent and received (type, quantity, sender/recipient, time)
- Blocks and mutes
e. Coins system data:
- Coins balance and transaction history (earning and spending)
- Monthly Coins statistics (calculated per calendar month and reset at the beginning of the month)
- Daily invitation count (a maximum of 4 invitations per day; the counter is reset at midnight)
- Login streaks and daily login data
- The times and types of activities for which Coins are awarded
f. Public Profile data (optional):
- Profile information (name, bio, category)
- Internal analytics data (likes, views, comments, shares โ not disclosed to third parties)
- Follower count and follower list
- Daily statistics (generated automatically)
g. Technical and automatically collected data:
- Device information โ model, operating system, app version
- IP address โ for security purposes and approximate location determination
- FCM token โ for push notifications (Firebase Cloud Messaging)
- Crash and error reports โ to improve app stability
- Email verification status โ whether your email address has been confirmed
h. Location data (only with explicit consent):
- GPS coordinates โ for the Social Map, location tagging in posts
- Place name โ e.g. "Berlin, Germany" (determined via reverse geocoding)
- Automatic updates โ every 5 minutes, only if location sharing is active
- Location data can be deactivated at any time in the privacy settings
i. Advertising data:
- Whether and when you have watched a rewarded advertisement (timestamp) โ for the Coins reward
- The number of advertisements watched per hour (max. 3 per hour)
- Google AdMob (Google LLC, USA) is used to display advertising. In addition, Unity Ads (Unity Technologies ApS) and InMobi (InMobi Pte. Ltd.) are integrated as advertising mediation partners and may deliver advertising via AdMob. On devices where you have consented to the app tracking request (iOS: App Tracking Transparency / ATT; Android: Advertising ID), these services may use your device identifier (IDFA on iOS / GAID on Android) for personalized advertising. Without your consent, only contextual advertising is displayed.
j. Content filter settings:
- Your selected content filter level (Normal, Sensitive, Hidden) โ stored locally and on the server
k. Data export log:
- The times at which you downloaded your data โ for security purposes
l. Problem reports:
- Reports submitted via the "Report a problem" function (Settings โ Help & Support), including the description, an optional screenshot and automatically attached device information (device model, operating system, app version)
m. Accent color settings:
- The accent color you have selected for app personalization โ stored locally and on the server
n. Video compression:
- When videos are uploaded, video compression is carried out automatically in order to reduce the file size. Compression takes place exclusively locally on your device before the video is uploaded. We do not store uncompressed original videos.
o. Offline cache:
- Content that has already been loaded (feed, profiles, chat histories) is cached locally on your device (up to 50 MB) so that it is also available without an internet connection. The cache is synchronized automatically once a connection is re-established. Locally cached data is not transferred to our servers unless you perform an action (e.g. create a post).
p. Islamic features:
- Prayer times (Namaz times) โ calculated on the basis of your location (GPS coordinates or a manually entered place). The calculation takes place locally on the device; no location data is sent to external servers.
- Hijri calendar โ Islamic date display, calculated locally.
- Qibla compass โ the direction of prayer is calculated locally on the basis of your location and the device compass.
- 99 Names of Allah โ static content; no user data is collected.
- Namaz streak โ your daily prayer tracking data (whether you prayed, streak counter, date) is stored in Firestore.
- Prayer notifications with an Azan sound โ local push notifications based on calculated prayer times. The Azan sound is played locally on the device.
q. Post translation:
- If you use the translation function, the post text is sent to the MyMemory translation API (Translated Srl, Italy). Only the text to be translated and the target language are transmitted โ no user IDs, no device data, and no IP addresses transmitted by us.
r. Voice input (speech-to-text):
- If you use the dictation function when creating posts, your speech is processed by your operating system's speech recognition system (Google Speech Recognition on Android / Apple Speech Recognition on iOS). Heartbeat Pakistan has no direct access to the raw data of the voice recording. Speech processing is carried out by the operating system and its services. The recognized text is displayed exclusively in the text field of the post editor and is only stored on our servers when a post is published. No voice recordings are stored or disclosed by Heartbeat Pakistan.
s. App security data (freeRASP):
- freeRASP (Runtime Application Self-Protection) collects anonymized security data for the detection of threats: root/jailbreak status, debugger detection, emulator detection, app integrity check, hooking detection, VPN detection, developer mode. This data is anonymized and contains no personal information. Detected threats are logged in Firebase Crashlytics.
t. Event data:
- Events created โ title, description, date, place and associated media (stored in Firestore and Cloudflare R2).
ยง 3 โ HOW WE USE YOUR DATA
We use your data for the following purposes:
- Provision of the Services โ creating an account, publishing posts, sending messages, managing friendships
- Verification โ confirmation of your email address and age verification (18+)
- Personalization โ feed algorithm based on your interests and interactions (see ยง 10)
- Friend suggestions โ based on mutual friends ("People you may also know")
- Notifications โ push notifications about new messages, likes, comments, friend requests (with your consent)
- Coins system โ management of the Coins balance, transaction history, login streaks, monthly statistics
- Profile analytics โ internal statistics for Public Profiles (likes, views, comments, follower development)
- Security โ protection against abuse, spam, fraud and unauthorized access
- Link safety โ checking shared links for phishing and malware (locally in the app, no external API)
- Moderation โ enforcement of the community guidelines (warnings, suspensions)
- Improvement โ error correction, app stability, performance optimization
- Rewarded advertising โ display of optional advertising for earning Coins (Google AdMob; personalized advertising only with your consent via ATT/Advertising ID)
- Voice input โ dictation function when creating posts via the operating system's speech recognition system
- Content filter โ storage of your filter settings in order to adjust content visibility
- Data export โ provision of your data in a machine-readable format (JSON)
- Gifts โ processing of gift transactions within the platform
- Polls โ storage and display of your polls as well as voting results
- Video compression โ automatic optimization of uploaded videos for faster uploads and lower data usage
- Problem reports โ processing of the technical problems and errors you report
- Accent colors โ storage of your color settings for personalizing the app
- Offline cache โ local caching of content that has already been loaded, for offline access
- Islamic features โ calculation of prayer times, the Hijri calendar, the Qibla direction and Namaz streak tracking
- Post translation โ translation of post text via the MyMemory translation API
- App security (freeRASP) โ runtime protection against tampering, rooting, debuggers and hooking
- Events โ creation and display of event posts
- Legal obligations โ compliance with statutory requirements and requests from authorities
WE NEVER SELL YOUR PERSONAL DATA TO THIRD PARTIES.
ยง 4 โ LEGAL BASES FOR PROCESSING
We process your data on the basis of the following legal bases (GDPR Art. 6 as the core standard):
- Performance of a contract (Art. 6(1)(b) GDPR) โ for the provision and use of the Services (account, posts, chat, friendships, Coins system, polls)
- Consent (Art. 6(1)(a) GDPR) โ for optional features: location sharing, push notifications, camera and microphone access, biometrics
- Legitimate interest (Art. 6(1)(f) GDPR) โ for security measures, link safety checks, feed personalization, friend suggestions, app improvement, video compression
- Legal obligation (Art. 6(1)(c) GDPR) โ for compliance with statutory requirements and requests from authorities
Withdrawal of consent: You may withdraw your consent at any time โ in the app settings under "Privacy" or "Permissions". Withdrawal does not affect the lawfulness of processing that was based on consent prior to the withdrawal.
ยง 5 โ CHAT MESSAGES
Private chat messages are stored in Firebase Firestore (Google LLC, USA) and transmitted exclusively encrypted via TLS 1.2+. Messages are stored on the Firebase servers in plain text.
Protective measures for chat messages:
- All transmissions are encrypted (TLS 1.2+)
- Firebase is certified under the EU-US Data Privacy Framework and EU standard contractual clauses
- The optional chat lock (PIN or biometrics) protects access to your chats at device level โ no one can view your messages without unlocking
- Old messages from the E2EE phase (prior to May 2026) are displayed as "[Old encrypted message โ no longer readable]"
Note: Heartbeat Pakistan and Firebase, as infrastructure service providers, have technical access to stored messages. Firebase processes messages exclusively as a processor in accordance with our data protection provisions (ยง 8) and may not use them for its own purposes.
ยง 6 โ APP SECURITY (PIN & BIOMETRICS)
Heartbeat Pakistan offers additional security mechanisms to protect your account:
- PIN lock โ You can set up a 4- or 6-digit PIN that is requested when the app is opened. The PIN is stored as a SHA-256 hash exclusively locally on your device in secure storage. After 5 failed attempts, the app is locked for 2 minutes. The plain-text PIN is never transmitted to our servers at any time.
- Biometric authentication โ You can use Face ID (iOS), Touch ID (iOS) or fingerprint (Android) to unlock the app. Biometric data is processed and stored exclusively by your device's operating system. Heartbeat Pakistan has no access to your biometric data โ we receive only a yes/no result of the authentication.
- Automatic background lock โ If you move the app to the background for more than 30 seconds and then return, the app lock screen (biometrics or PIN) is displayed automatically. This protects your data if the device is left briefly unattended. The timestamps are held exclusively locally in the app's working memory and are not transmitted.
- Chat lock โ You can protect your chats additionally with a PIN or biometrics. The chat lock requires authentication before the chat area can be accessed. The setting is stored as a boolean value (enabled/disabled) in your session settings in Firestore. No additional biometric data is collected โ authentication takes place via the same local mechanism as the app lock.
- Login notifications โ You can be notified when someone logs in to your account.
- Log out all devices โ You can terminate all active sessions.
One-time permission request: Following your first sign-in or registration, you will be asked once to grant all required device permissions (camera, microphone, photos, location, notifications). You may decline individual permissions โ declined permissions are marked in red and can be activated directly in the system settings via an "Open settings" button. Declined permissions can be granted subsequently at any time in your device settings. The information as to whether the permission request has already been carried out is stored exclusively locally on your device (SharedPreferences).
Media download: Received chat images and videos can be saved directly to the device gallery by long-pressing the message or in the full-screen viewer. This process requires the photo/gallery permission. The saved files remain exclusively on your device โ no further processing by Heartbeat Pakistan takes place.
ยง 7 โ DATA STORAGE & SECURITY
Your data is stored with the following providers:
- Firebase / Google Cloud (Firestore, Auth, FCM) โ for user data, authentication, chat messages, posts, comments, likes, friendships, settings, Coins data, polls, profile analytics, push notifications. Current server location: USA. A migration to the EU (europe-west) is planned.
- Cloudflare R2 โ for all media files (profile pictures, banner images, post photos, post videos, story media, chat media, thumbnails, stream media). Cloudflare R2 uses a global network with S3-compatible storage.
Security measures:
- Encryption in transit (TLS 1.2+ / SSL)
- Encryption at rest (Google Cloud / Cloudflare standard encryption)
- Passwords stored as cryptographic hashes (Firebase Auth)
- PIN stored locally as a SHA-256 hash
- R2 credentials held securely in environment variables (.env), not in the client code
- freeRASP (Runtime Application Self-Protection) โ runtime protection against root/jailbreak, debuggers, app tampering, hooking frameworks and malware
- Cloudflare Workers โ server-side validation of media uploads and API token verification
ยง 8 โ DISCLOSURE TO THIRD PARTIES & PROCESSORS
WE DO NOT SELL YOUR PERSONAL DATA.
Processors (process data on our behalf):
- Google / Firebase (Google LLC, USA) โ Firestore database, Firebase Authentication, Firebase Cloud Messaging, Firebase Hosting
- Cloudflare (Cloudflare, Inc., USA) โ R2 object storage for all media files, CDN for web hosting, Cloudflare Workers for server-side API validation (media uploads, token verification)
- Agora (Agora.io, Inc., USA) โ real-time audio and video transmission for direct calls (audio/video), community group rooms and live streams. When you use these features, your audio and/or video data is transmitted and processed via Agora's global network infrastructure. In doing so, Agora processes connection quality data, channel IDs (which are derived from anonymized user IDs) and technical metadata (device type, network conditions). Heartbeat Pakistan has no access to the content (audio/video) of calls or streams. Agora servers are located worldwide (USA, EU, Asia). Agora's privacy policy: https://www.agora.io/en/privacy-policy/
- Google AdMob (Google LLC, USA) โ display of advertising in the app. With your consent (iOS: App Tracking Transparency / ATT; Android: Advertising ID), Google AdMob may use your device identifier (IDFA/GAID) for personalized advertising. Without consent: exclusively contextual advertising. Privacy policy: https://policies.google.com/privacy
- Unity Ads (Unity Technologies ApS, Denmark) โ advertising mediation via Google AdMob. Unity Ads may deliver advertising within the framework of AdMob mediation and in doing so process technical data (device type, operating system, language, approximate location). The use of your device identifier for personalized advertising takes place only with your consent (ATT/Advertising ID). Privacy policy: https://unity.com/legal/privacy-policy
- InMobi (InMobi Pte. Ltd., Singapore) โ advertising mediation via Google AdMob. InMobi may deliver advertising within the framework of AdMob mediation and in doing so process technical data (device type, operating system, language, approximate location). The use of your device identifier for personalized advertising takes place only with your consent (ATT/Advertising ID). Privacy policy: https://www.inmobi.com/privacy-policy/
Third-party APIs (data is sent to their servers when used):
- Giphy (Meta Platforms, USA) โ GIF search and display in chat. Search queries are sent to the Giphy API.
- Deezer (Deezer SA, France) โ music search and preview URLs for music in posts/stories. Search queries are sent to the Deezer API.
- MusicBrainz (MetaBrainz Foundation, USA) โ music metadata search. Search queries are sent.
- Saavn / JioSaavn (Saavn Media, India) โ music search. Search queries are sent.
- Twemoji CDN / jsdelivr โ for static sticker images. Only image URLs are loaded; no user data is sent.
- Google Fonts (Noto Emoji) โ for animated emoji stickers. Only image URLs are loaded.
- MyMemory (Translated Srl, Italy) โ for post translation. Post text and the target language are sent to the MyMemory API. No user IDs or device data are transmitted.
- Wikimedia Commons / Freesound.org โ Azan audio files for prayer notifications. Static audio files that are embedded in the app. No user data is sent to these services.
Disclosure to authorities:
We disclose data to law enforcement authorities where we are legally obliged to do so. Chat messages are stored on the Firebase servers in plain text (since May 2026 โ E2EE was removed) and may be handed over in the context of a legally effective request from the authorities.
ยง 9 โ RETENTION PERIODS
We store your data only for as long as is necessary for the respective purpose:
- Account data (profile, email, date of birth) โ for as long as your account is active. After account deletion: deleted within 90 days.
- Posts, virals, comments, polls โ for as long as your account is active or until you delete them manually.
- Stories โ automatically deleted after 24 hours.
- Chat messages โ for as long as the chat exists or until a participant deletes them.
- Friends list & requests โ for as long as the account is active.
- Coins data โ the monthly statistics are reset at the beginning of the month. Transaction history: for as long as the account is active.
- Location data โ last known position. Deleted when location sharing is deactivated.
- FCM token โ deleted upon logout, change of device or account deletion.
- Profile analytics โ for as long as the Public Profile exists.
- Login data & security logs โ up to 12 months for security purposes.
- Problem reports โ up to 12 months after processing, then deleted.
- Offline cache โ stored locally on your device; automatically deleted upon account deletion or uninstallation of the app.
- Namaz streak data โ for as long as the account is active. Upon account deletion: deleted within 90 days.
- Prayer time settings โ stored locally on the device; deleted upon uninstallation.
- Backup copies โ may continue to exist for up to 90 days after deletion for technical reasons.
After account deletion, all of your data will be removed from our active systems within 90 days, unless statutory retention obligations exist. Content that has already been shared or quoted by other users may continue to exist in anonymized form.
Before your account is finally deleted, you will be asked to read through the Terms of Service and this Privacy Policy again and to confirm expressly that you agree to the deletion.
ยง 10 โ AUTOMATED DECISIONS & PROFILING
Heartbeat Pakistan uses automated systems that process your usage data. None of these decisions has legal or similarly significant effects on you.
a. Feed algorithm (personalization):
Your feed is sorted by an algorithm that takes the following factors into account:
- Engagement โ likes, comments, shares and views of a post
- Interests โ hashtags with which you interact frequently
- Recency โ newer posts are given preference
- Relationship โ posts from friends receive a bonus
- Boost โ posts can be highlighted using Coins
b. Friend suggestions:
We suggest users to you who have mutual friends with you ("friends of friends"). No external data sources (e.g. phone book, email contacts) are used.
c. Link safety check:
Links that are shared in the app are checked locally on the device against a list of known safe domains. No links are sent to external servers for checking.
d. Content moderation:
Reported content is reviewed by us. We currently do not use automated content moderation or AI. All moderation decisions are made manually.
ยง 11 โ INTERNATIONAL DATA TRANSFERS
Because we use services from Google (Firebase), Cloudflare, Agora and Google AdMob, your data may be transferred to the USA and other countries outside your country of residence. We ensure that the following safeguards are in place:
- EU-US Data Privacy Framework (DPF) โ Google LLC and Cloudflare, Inc. are certified under the EU-US Data Privacy Framework.
- EU standard contractual clauses (SCCs) โ Our data processing agreements with Google, Cloudflare and Agora contain Standard Contractual Clauses in accordance with the decision of the EU Commission.
- Encryption โ All data transmissions are encrypted (TLS 1.2+).
- Agora infrastructure โ Agora operates global data centers (USA, EU, Asia-Pacific). Audio/video data for calls and live streams is routed via the nearest Agora region in each case.
Planned: We plan to migrate our Firebase instance from the USA to the EU (europe-west).
ยง 12 โ BIOMETRIC DATA
Biometric data (fingerprint, facial recognition) for the optional app lock and chat lock is processed and stored exclusively locally on your device by the operating system. Heartbeat Pakistan:
- has no access to your biometric data
- stores no biometric data on our servers
- transmits no biometric data over the internet
- receives only a yes/no result from the operating system
ยง 13 โ CHILD PROTECTION & MINIMUM AGE
Our Services are intended exclusively for persons aged 18 and over. Upon registration, the date of birth is requested and age verification is carried out. We do not knowingly collect personal data from minors.
If we learn that a minor has created an account, we will delete the account and all associated data without delay. Parents or legal guardians can find our contact details in the legal notice (imprint): https://heartbeatpakistan.com
Heartbeat Pakistan has a zero-tolerance policy toward child sexual abuse and exploitation (CSAM/CSAE). Content or behavior that sexualizes minors is expressly prohibited and will be removed immediately. Offending accounts are permanently banned and the case is reported to the competent authorities. See our published Child Safety Standards. To report such content, contact us at: support@heartbeatpakistan.com
ยง 14 โ YOUR RIGHTS
Depending on your country of residence, you have various rights in respect of your personal data. The following rights apply as a minimum standard for all users:
- Right of access โ Find out which data we have stored about you
- Right to rectification โ Correct inaccurate data
- Right to erasure โ Delete your account and your data (Settings โ Account โ Delete account)
- Right to restriction โ Restrict the processing of your data
- Data portability โ Download your data as a JSON file (Settings โ Account โ My Data)
- Right to object โ Object to the processing of your data
- Right of withdrawal โ Withdraw your consent at any time
In order to exercise your rights, use the functions in the app or contact us via the legal notice (imprint): https://heartbeatpakistan.com โ We process your request within 30 days.
You can find further country-specific rights in Part B.
ยง 15 โ COOKIES & TRACKING
Our mobile app does not use cookies. We do not use Google Analytics and we do not use the Facebook Pixel.
The following services automatically collect data during the operation of the app:
- Firebase Cloud Messaging โ for push notifications (FCM token)
- Firebase Crashlytics (if enabled) โ for crash reports
- Google AdMob โ for the display of rewarded advertising. AdMob may use your device identifier (IDFA on iOS / Advertising ID on Android) if you have consented to the corresponding permission request (iOS: App Tracking Transparency / ATT dialog; Android: Advertising ID setting). Without your consent, only contextual advertising is served, without the use of device identifiers.
App Tracking Transparency (iOS 14.5+):
When you first launch the app on iOS, you will be asked via the App Tracking Transparency (ATT) system dialog whether you consent to the use of your device identifier (IDFA) for personalized advertising. If you consent, your IDFA will be transmitted to Google AdMob. If you decline, you will see exclusively non-personalized advertising. You can withdraw your consent at any time in the iOS settings under Privacy & Security โ Tracking.
You can deactivate push notifications at any time in the app settings.
ยง 16 โ DATA EXPORT & DATA PORTABILITY
You can download a copy of all of your personal data in the app: Settings โ Account โ My Data โ Download data.
The export contains: profile data, posts, comments, stories, friends list, chat messages, likes, friend requests and settings. The data is exported as a JSON file.
PART B โ Regional Privacy Information
The following sections contain additional information that applies specifically to users in certain countries or regions.
ยง 17 โ ๐ช๐บ EU/EEA โ GDPR
If you are resident in the European Economic Area (EEA), the provisions of Regulation (EU) 2016/679 (GDPR) apply.
Additional rights:
- Right to lodge a complaint (Art. 77) โ with the competent data protection supervisory authority of your country (list: edpb.europa.eu)
- Automated decisions (Art. 22) โ We do not make any automated decisions with legal effect.
- Withdrawal of consent (Art. 7(3)) โ Possible at any time (see ยง 4).
- Data protection officer โ If you have questions about data protection, you can reach us at: support@heartbeatpakistan.com. We are currently examining whether the designation of a formal data protection officer pursuant to Art. 37 GDPR is required.
- Data breaches (Art. 33, 34 GDPR) โ In the event of a personal data breach, we will notify the competent supervisory authority within 72 hours, and affected users where there is a high risk to their rights and freedoms.
Data transfers: Transfers to the USA take place on the basis of the EU-US Data Privacy Framework and EU standard contractual clauses (SCCs).
Online dispute resolution: https://ec.europa.eu/consumers/odr
ยง 18 โ ๐ฌ๐ง UK โ UK GDPR
If you are resident in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply.
Complaints body: Information Commissioner's Office (ICO) โ ico.org.uk
Data transfers: On the basis of the UK Extension to the EU-US Data Privacy Framework and the UK IDTA or the UK Addendum to the EU SCCs.
ยง 19 โ ๐จ๐ญ SWITZERLAND โ FADP
If you are resident in Switzerland, the provisions of the revised Federal Act on Data Protection (FADP / DSG, in force since September 1, 2023) apply in addition.
Complaints body: Federal Data Protection and Information Commissioner (FDPIC) โ edoeb.admin.ch
ยง 20 โ ๐น๐ท TURKEY โ KVKK
If you are resident in Turkey, the provisions of the KVKK (Law No. 6698) apply.
Your rights under Art. 11 KVKK:
- The right to learn whether your data is being processed
- The right to information about the processing
- The right to rectification of incomplete or inaccurate data
- The right to erasure or destruction of your data
- The right to object to processing carried out solely by automated means
- The right to compensation in the event of unlawful processing
Data transfers: With your explicit consent given upon registration pursuant to Art. 9 KVKK.
Complaints body: Kiลisel Verileri Koruma Kurumu (Personal Data Protection Authority) โ kvkk.gov.tr
ยง 21 โ ๐ธ๐ฆ๐ฆ๐ช๐ถ๐ฆ ARAB COUNTRIES
Saudi Arabia (PDPL): You have rights of access, rectification and erasure. Complaints body: SDAIA โ sdaia.gov.sa
United Arab Emirates (PDPL): Rights of access, rectification, erasure, restriction and portability. Complaints body: UAE Data Office โ uaedataoffice.ae
Qatar (Law No. 13/2016): Rights of access, rectification and erasure.
Bahrain (Law No. 30/2018): Rights of access, rectification, erasure and objection.
ยง 22 โ ๐ต๐ฐ PAKISTAN
Pakistan currently has no comprehensive data protection law. The Prevention of Electronic Crimes Act (PECA) 2016 and Article 14 of the Constitution protect your privacy.
Irrespective of this, we grant you the same rights as described in ยง 14.
Content moderation: Heartbeat Pakistan complies with the requirements of the Pakistan Telecommunication Authority (PTA).
ยง 23 โ ๐ฆ๐ซ AFGHANISTAN
Afghanistan currently has no comprehensive data protection law. Article 37 of the Afghan Constitution (2004) guarantees the right to privacy of communications.
As a user in Afghanistan, we grant you the same data protection rights as all other users.
ยง 24 โ ๐ฎ๐ณ INDIA โ DPDPA 2023
If you are resident in India, the provisions of the Digital Personal Data Protection Act, 2023 (DPDPA) apply.
Your rights:
- Right of access (Sec. 11)
- Right to rectification and erasure (Sec. 12)
- Right to lodge a grievance (Sec. 13) โ with the Data Protection Board of India
- Right to nominate a nominee (Sec. 14) โ in the event of death
Child protection: The DPDPA prohibits the tracking of minors. Our minimum age of 18 years satisfies this requirement.
ยง 25 โ ๐บ๐ธ USA โ CCPA/CPRA & STATE PRIVACY LAWS
If you are resident in California (CCPA/CPRA):
- Right to Know
- Right to Delete โ Settings โ Account โ Delete account
- Right to Opt-Out โ We do not sell your data.
- Right to Non-Discrimination
- Right to Correct
- Right to Limit the use of sensitive data
Categories of data collected (CCPA): identifiers, personal information, age, internet activity, geolocation, audio/visual, interest profile.
DO NOT SELL OR SHARE: We do not sell or share your data for advertising purposes.
Further US states with privacy laws: Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Oregon, Texas, Montana, Iowa, Indiana, Tennessee.
COPPA: Since our minimum age is 18 years, we do not collect data from children under 13.
ยง 26 โ ๐จ๐ฆ CANADA โ PIPEDA & QUEBEC LAW 25
If you are resident in Canada, PIPEDA applies and โ for Quebec โ Loi 25 applies in addition.
Your rights: access, rectification, withdrawal of consent, complaint.
Complaints body: Office of the Privacy Commissioner of Canada โ priv.gc.ca
Quebec: Commission d'accรจs ร l'information du Quรฉbec (CAI) โ cai.gouv.qc.ca
ยง 27 โ ๐ฆ๐บ AUSTRALIA โ PRIVACY ACT & APPs
If you are resident in Australia, the Privacy Act 1988 and the Australian Privacy Principles (APPs) apply.
Your rights: access & correction (APP 12, 13), anonymity (APP 2), right to complain (APP 1).
Cross-border disclosure (APP 8): We ensure that Google and Cloudflare adhere to comparable standards.
In the event of data breaches: notification in accordance with the Notifiable Data Breaches (NDB) Scheme.
Complaints body: Office of the Australian Information Commissioner (OAIC) โ oaic.gov.au
ยง 28 โ ๐ฎ๐ท IRAN
Iran has no comprehensive data protection law. Article 25 of the Iranian Constitution guarantees the secrecy of correspondence and the right to confidentiality of communications. As a user in Iran, we grant you the same data protection rights as all other users (see ยง 14).
Note: Internet use in Iran is subject to regulatory restrictions. Use of Heartbeat Pakistan is at your own responsibility.
ยง 29 โ ๐ท๐บ RUSSIA โ PERSONAL DATA LAW (FZ-152)
If you are resident in Russia, the provisions of Federal Law No. 152-FZ "On Personal Data" apply.
Your rights: access, rectification, erasure, withdrawal of consent, complaint.
Data localization: Art. 18(5) FZ-152 requires the storage of the personal data of Russian citizens on servers in Russia. We are currently examining implementation. Until then, Russian users consent to international data storage.
Complaints body: Roskomnadzor (Federal Service for Supervision in the Sphere of Telecommunications) โ rkn.gov.ru
ยง 30 โ ๐ง๐ฉ BANGLADESH โ DIGITAL SECURITY LAW & DSA 2018
Bangladesh currently has no comprehensive data protection law. The Digital Security Act 2018 and Article 43 of the Constitution protect privacy.
As a user in Bangladesh, we grant you the same data protection rights as all other users (see ยง 14).
Content moderation: Heartbeat Pakistan complies with the requirements of the Bangladesh Telecommunication Regulatory Commission (BTRC).
ยง 31 โ ๐ฎ๐ฉ INDONESIA โ UU PDP (LAW NO. 27/2022)
If you are resident in Indonesia, the provisions of the Undang-Undang Pelindungan Data Pribadi (UU PDP), Law No. 27/2022, apply.
Your rights: access, rectification, erasure, restriction, objection, portability.
Consent: Your explicit consent given upon registration covers the data processing.
Content moderation: Compliance with the ITE laws (UU ITE) and instructions from the Ministry of Communication and Informatics (Kominfo).
Complaints body: Kominfo โ kominfo.go.id
ยง 32 โ ๐บ๐ฟ๐น๐ฏ๐น๐ฒ๐ฐ๐ฌ๐ฐ๐ฟ CENTRAL ASIA (Uzbekistan, Tajikistan, Turkmenistan, Kyrgyzstan, Kazakhstan)
The countries of Central Asia have differing data protection standards:
Uzbekistan ๐บ๐ฟ: Law "On Personal Data" (2019). Rights: access, rectification, erasure.
Kazakhstan ๐ฐ๐ฟ: Law "On Personal Data and its Protection" (No. 94-V, 2013). Rights: access, rectification, erasure, withdrawal.
Kyrgyzstan ๐ฐ๐ฌ: Law "On Personal Data" (2008). Rights: access, rectification, erasure.
Tajikistan ๐น๐ฏ: Law "On Personal Data" (2018). Rights: access, rectification.
Turkmenistan ๐น๐ฒ: No comprehensive data protection law. The Constitution protects privacy.
For all users in Central Asia, at least the same rights apply as described in ยง 14.
ยง 33 โ ๐ฒ๐พ MALAYSIA โ PDPA 2010
If you are resident in Malaysia, the provisions of the Personal Data Protection Act 2010 (PDPA, Act 709) apply.
Your rights: access (Sec. 12), rectification (Sec. 34), withdrawal of consent (Sec. 38), prevention of direct marketing (Sec. 39).
Data localization: Art. 129 PDPA governs cross-border data transfers. Your consent given upon registration authorizes international storage.
Complaints body: Jabatan Perlindungan Data Peribadi (JPDP) โ pdp.gov.my
ยง 34 โ ๐ง๐พ BELARUS โ DATA PROTECTION LAW (NO. 99-Z)
If you are resident in Belarus, the provisions of Law No. 99-Z "On the Protection of Personal Data" (2021) apply.
Your rights: access, rectification, erasure, withdrawal of consent, complaint.
Complaints body: National Center for Personal Data Protection โ cpd.by
PART C โ Final Provisions
ยง 35 โ CHANGES TO THIS POLICY
We may update this Policy from time to time. In the event of material changes, we will notify you via the app. The current version can be viewed at any time in the app and on our website.
ยง 36 โ COMPLAINTS BODIES
Complaints bodies:
๐ช๐บ EU/EEA: Competent supervisory authority โ edpb.europa.eu
๐ฌ๐ง UK: ICO โ ico.org.uk
๐จ๐ญ Switzerland: FDPIC โ edoeb.admin.ch
๐น๐ท Turkey: KVKK โ kvkk.gov.tr
๐ธ๐ฆ Saudi Arabia: SDAIA โ sdaia.gov.sa
๐ฆ๐ช UAE: UAE Data Office โ uaedataoffice.ae
๐ฎ๐ณ India: Data Protection Board of India
๐บ๐ธ USA (California): California Attorney General โ oag.ca.gov/privacy
๐จ๐ฆ Canada: OPC โ priv.gc.ca
๐ฆ๐บ Australia: OAIC โ oaic.gov.au
๐ท๐บ Russia: Roskomnadzor โ rkn.gov.ru
๐ฎ๐ฉ Indonesia: Kominfo โ kominfo.go.id
๐ฒ๐พ Malaysia: JPDP โ pdp.gov.my
๐ง๐พ Belarus: CPD โ cpd.by
COPYRIGHT
All content of this Privacy Policy is copyright-protected property of Schwaben Apps. The name "Heartbeat Pakistan", the app logo and all associated identifying marks are trademarks of Schwaben Apps.
Last updated: August 22, 2026
ยฉ 2026 Schwaben Apps / Heartbeat Pakistan. All rights reserved.