nanara
Apps Guides About Contact ES

Privacy and personal data processing policy

NomiNest — Nanara S.A.S. · Version 2.0 · September 20, 2026

This is a courtesy translation provided for convenience. The Spanish version published at nanara.co/privacidad is the legally binding version.

Nanara S.A.S. (hereinafter, “Nanara”), a company duly incorporated under the laws of the Republic of Colombia, with Tax ID (NIT) 902.081.708-4 and domiciled at Cra. 4 N.° 80A – 16, in the city of Bogotá D.C. (Colombia), in accordance with the legislation in force on Habeas Data and Personal Data Protection, specifically Statutory Law 1581 of 2012 and Decree 1377 of 2013, hereby makes its Privacy Policy known to Data Subjects. This Policy applies to the users of the Applications (as defined below).

Nanara develops a family of mobile Applications for tracking and managing personal information throughout the life cycle, which operate as a centralized data repository (the “Application” or the “Applications”). The current Applications and their users are described in the annexes that form an integral part of this Policy. Each annex identifies the Application, the Data Subject, the categories collected, the type of data processed and their purposes.

The Applications allow users (fathers, mothers, legal representatives, caregivers or the Data Subjects themselves, as applicable) to record, store, organize and consult health and development information in a unified way, thus facilitating review, historical tracking, quick access to the information and, when the user so authorizes, the possibility of sharing that information with health professionals.

In this Policy you will find explanatory information on how your personal data is handled, the purpose on which the Processing is based and your rights as a Data Subject.

1. Definitions

(a) “Authorization”: The prior, express and informed consent of the Data Subject to carry out the Processing of personal data.

(b) “Database”: An organized set of personal data that is subject to Processing.

(c) “Personal data”: Any piece of information linked to one or more identified or identifiable persons, or that may be associated with a natural or legal person.

(d) “Sensitive data”: Data that affect the privacy of the Data Subject or whose improper use may lead to discrimination, such as data revealing racial or ethnic origin, political orientation, religious or philosophical beliefs, membership in trade unions, social or human rights organizations or organizations that promote the interests of any political party or that guarantee the rights and guarantees of opposition political parties, as well as data relating to health and sex life, and biometric data.

(e) “Data Processor”: A natural or legal person, public or private, who by itself or in association with others carries out the Processing of personal data on behalf of the Data Controller.

(f) “Data Controller”: A natural or legal person, public or private, who by itself or in association with others decides on the database and/or the Processing of the data.

(g) “Data Subject”: The natural person whose personal data is subject to Processing.

(h) “Transfer”: Occurs when the data controller and/or processor, located in Colombia, sends personal information to a recipient who is in turn a data controller and is located inside or outside the country.

(i) “Transmission”: Processing of personal data that involves sending the data inside or outside the territory of the Republic of Colombia for the purpose of Processing by the processor on behalf of the controller.

(j) “Processing”: Any operation or set of operations on personal data, such as collection, storage, use, circulation or deletion.

(k) “Users”: Persons of legal age who use any of the Applications to manage health information about themselves or about third parties in their care, as the case may be and in accordance with the annexes to this Policy.

2. Processing

Nanara, as Data Controller, will carry out the following operations on the Data Subject’s personal data, including but not limited to: collection, storage, use, Processing, transmission, transfer and, where applicable, deletion of the personal data.

The foregoing includes, without limitation, sending personal data to our service providers and collaborators who support the development, maintenance and operation of the platform, in order to ensure the proper operation of the Application and all its internal tools.

3. Personal data we collect

The Applications allow the recording and tracking of data (including personal data) across different and specific stages of people’s life cycle. The scope and depth of the personal data collected will depend exclusively on the information the user voluntarily decides to provide through any of the Applications. At all times, whoever provides the information will have control over the data recorded and may modify, update or delete it whenever they consider it necessary.

The personal data you voluntarily provide may correspond, depending on the Application concerned, to the categories set out in the annexes to this Policy, according to the relevant stage.

4. Personal data of third parties

The Applications may store personal data of persons who are not direct users, such as emergency contacts, treating health professionals, invited caregivers, the person authorized to make health decisions and the person with whom tracking is shared, among others.

A user who records third-party data declares that they are duly authorized to provide it and that they have informed those third parties about the Processing and its purposes. Third parties whose data has been recorded may exercise their habeas data rights through the same procedures established in the Policy. Nanara will not be liable for third-party information provided by the user without due authorization.

5. General purposes of the Processing

Without prejudice to the specific purposes of the Processing set out and individualized in the corresponding annexes to this Policy, Nanara will process the data while guaranteeing respect for the rights of the Data Subjects registered in its various databases, and in particular for the purposes described below:

Stakeholder groupPurposes
Users• Managing the contractual relationship between the user and Nanara, including registration, access to and use of the corresponding Application;
• Creating and managing the user’s account, including authentication, password recovery and preference settings;
• Handling the user’s petitions, complaints, claims and inquiries;
• Sending communications related to the service, including Application updates, changes to the terms and conditions, and security notifications;
• Conducting studies, surveys and statistical analyses to improve the user experience and the services of the corresponding Application;
• Complying with applicable legal, accounting, tax and regulatory obligations; and
• Preventing fraudulent or unlawful activities and ensuring the security of the platform.
CollaboratorsNanara may share the Data Subject’s personal data with health professionals and institutions when the Data Subject or their legal representative expressly authorizes it. This includes, without limitation:
• General practitioners, specialists, gynecologists, obstetricians, pediatricians, geriatricians and other treating health professionals;
• Hospitals, clinics and health centers where the Data Subject receives medical care;
• Clinical laboratories and diagnostic centers;
• Nutrition, physiotherapy, occupational therapy and development professionals;
• Health promoting entities (EPS) and health service provider institutions (IPS);
• Other health professionals authorized by the Data Subject or their legal representative.
The purpose of sharing this information is to facilitate the Data Subject’s medical care, to provide a complete and up-to-date medical history (subject to the accuracy, sufficiency and currency of the information provided by the user), and to seek to improve the quality of health care.
Service providersThe purposes of the transmission and/or transfer of personal data to service providers and data processors include:
• Ensuring the secure storage of personal data on cloud servers and technology infrastructure;
• Processing payments, subscriptions and transactions related to the use of the Application;
• Developing, maintaining, updating and improving the features of the Applications;
• Performing data analysis, statistics and studies to improve the user experience and the services offered;
• Providing customer service and technical support and resolving incidents related to the use of the Applications;
• Ensuring information security, data protection and the prevention of unauthorized access or fraudulent activities;
• Sending notifications, emails, text messages and other communications related to the service;
• Complying with applicable legal, accounting, tax, audit and regulatory obligations;
• Responding to requests from competent authorities when there is a legal obligation to report information; and
• Ensuring the proper functioning, operation and continuous improvement of the Applications.
Nanara will require service providers and data processors to comply with adequate personal data protection standards.
The data processors in place as of the date of this Policy can be identified in the corresponding annexes. The list of processors may change; its updated version will always be available in the Policy in force published at nanara.co/privacidad.

6. Authorization

The Processing of Personal Data by Nanara requires the free, prior, express and informed consent of the Data Subject. Nanara will at all times keep a record of the authorization given by the Data Subject, through suitable means that guarantee that it was given expressly, freely, in advance and on an informed basis, such as written authorizations, authorizations given by electronic means or upon accepting the terms and conditions of services and/or products, the corresponding policy supporting the Processing of Personal Data, or any other mechanism that makes it possible to evidence and demonstrate a registration, access to or relationship with Nanara’s services and/or products.

7. Rights of Data Subjects

Data Subjects whose Personal Data are Processed will have the rights provided for in Law 1581 of 2012 and in all regulations that implement, add to or complement it, including:

  • a) To know, update and rectify their personal data.
  • b) To request proof of the authorization granted, except where it is expressly exempted as a requirement for the Processing.
  • c) To be informed by Nanara or any Data Processor, upon request, of the use made of their personal data.
  • d) To file complaints with the Superintendence of Industry and Commerce for violations of Law 1581 of 2012 and the other regulations that amend, add to or complement it.
  • e) To revoke the authorization and/or request the deletion of the data when the Processing does not respect constitutional and legal principles, rights and guarantees.
  • f) To access, free of charge, their personal data that has been subject to Processing.

8. Transfers and transmissions of personal data

Provided that the Data Subject gives their prior, express and informed authorization for the transfer or transmission of their data, Nanara may Transfer data to other Controllers to fulfill the purposes described in this Policy. If necessary, Transfers of personal data may take place within Colombia or to any other country, supported by the express and unequivocal authorization granted by the Data Subject under article 26 of Law 1581 of 2012.

In addition, Nanara may Transmit data to Data Processors, such as our auditors, lawyers, external advisors and our product or service providers. Transmissions of data may be national or international, within the framework of the data transmission agreements that may be entered into with the Data Processors under article 25 of Decree 1377 of 2013.

9. Inquiries and Claims

For the effective exercise of your rights, the personal data protection area or, failing that, the legal representative of Nanara S.A.S. will be responsible for handling petitions, inquiries and claims. Accordingly, Nanara S.A.S. has made the following channels available to you:

Company nameNANARA S.A.S.
Tax ID (NIT)902.081.708-4
DomicileCra. 4 N.° 80A – 16, Bogotá D.C., Colombia
Customer service phone+57 318 095 6969
Email for customer service and exercise of rightsdev@nanara.co
Responsible areaLegal Representative of NANARA S.A.S.
Website where the policy is publishednanara.co/privacidad

9.1. Inquiries

You and/or your successors in title may consult your personal data free of charge once every calendar month and whenever there are substantial changes to the personal data Processing policy. To do so, you must send a request to dev@nanara.co, which must contain the following information: (i) name and domicile of the Data Subject (or of the person authorized for this purpose) or any other means for receiving a response to the request; (ii) documents evidencing the identity of the Data Subject, or of the person so authorized; (iii) the description and purpose of the inquiry; and (iv) the name of the corresponding Application.

Nanara must respond to the request within ten (10) business days following its receipt. It must also state whether the request has any cost. If it is not possible to respond within that period, Nanara must inform the requester of the reasons for the delay and indicate a new date for the response, which may not exceed five (5) business days after the expiry of the first period.

9.2. Claims

Through a claim, you may file complaints for non-compliance with this Policy and/or the applicable Law, or request the correction, updating or deletion of your personal data.

To do so, you must send a claim to the email address indicated above, which must contain the following information: (i) name and domicile of the Data Subject (or of the person authorized for this purpose) or any other means for receiving a response to the request; (ii) documents evidencing the identity of the Data Subject or of the person so authorized; (iii) the description and purpose of the claim; (iv) the name of the corresponding Application; and (v) where applicable, any other documents or evidence to be relied on.

If the claim is incomplete, Nanara will ask you to complete the information within five (5) business days following its receipt. If, two (2) months after the date of that request, you have not provided the missing information, you will be deemed to have withdrawn the claim.

If the claim is complete, Nanara must respond within fifteen (15) business days following its receipt. If it is not possible to respond within that period, Nanara must explain the reasons for the delay and indicate a new date for the response, which may not exceed eight (8) business days after the expiry of the first period. If Nanara is not competent to handle your claim, it will forward it to the appropriate party within a maximum of two (2) business days and will inform you accordingly.

10. Term of the database

The databases will remain in force for as long as the Company exists and carries out the activities of its corporate purpose, while the purposes of the Processing persist, or until the Data Subject requests the deletion of their data.

11. Retention and deletion of data

11.1. Term. Personal data is kept for as long as the user’s account remains active and the data continues to be necessary for the purposes described in this Policy.

11.2. Retention period. Once the account has been deactivated, the data will be kept for a period of ten (10) years, unless the user uses the total deletion option provided for in the following paragraph.

11.3. Total deletion. The user may delete their account and all associated data at any time from within the Application, in the profile section. Deletion is immediate and irreversible.

If you have lost access to the Application, you may request it by writing to dev@nanara.co from the email address associated with your account; the request will be handled within the time limits for handling claims established in the Policy.

11.4. Partial deletion. It is not necessary to delete the whole account in order to delete specific information. The Data Subject, or their representative, may request the deletion of specific data through the same email address, keeping their account and the rest of the information. The same time limit and right of deletion apply.

The annex for each Application specifies which categories of data and information can be deleted partially and totally.

11.5. Propagation to processors. Where applicable, the deletion is communicated to the data processors so that they carry it out in their own systems.

11.6. What is retained? Only the records that the law requires to be kept are retained (in particular the record of the authorizations granted by the Data Subject, which serves as proof of the authorization), blocked for any other use. Backup copies are purged in the normal backup cycles.

12. Confidentiality and security measures

Your personal data will be kept in databases with security measures that protect the confidentiality of your information and, in particular, protect it against damage, loss, alteration, destruction or unauthorized use, access or Processing.

13. Amendments and/or Updates to this Policy

Nanara may amend this Policy. Substantial changes, especially those affecting the Processing of sensitive data or of persons under special protection, will be notified within the Application and will require new consent before continuing to use it. The version in force will be identified by its version number and will always be published at nanara.co/privacidad (English translation at nanara.co/en/privacy).

ANNEX A — NomiNest

This annex forms an integral part of the Privacy and Personal Data Processing Policy of NANARA S.A.S. and applies exclusively to the NomiNest Application, whose purpose is tracking child rearing and child care.

Given the age of the Data Subjects covered by NomiNest (early childhood), it is not necessary to take the minor’s opinion into account for the purposes of authorizing the Processing, which corresponds to the father, mother or legal representative.

1.1. Users and Data Subjects

The users of NomiNest are the fathers, mothers or legal representatives of the minor.

The Data Subjects of the personal data are children and adolescents, and the Processing of their data requires the prior, express and informed authorization of the father, mother or legal representative.

In accordance with article 7 of Law 1581 of 2012 and article 12 of Decree 1377 of 2013, the Processing of personal data of children and adolescents is permitted provided that it responds to and respects the best interests of the minors and ensures respect for their fundamental rights.

1.2. Data of Children and Adolescents

The personal data of children and adolescents that may be collected include, without limitation:

  • a) Identification data: full name, date of birth, age, sex, place of birth, photographs and relationship to the user.
  • b) Health data: medical history, diagnoses, health conditions, food allergies and intolerances, medications, blood type, hospitalizations and details of the treating health professional.
  • c) Growth and development data: weight, height, head circumference, growth curves, developmental milestones (motor, cognitive, language and socio-emotional) and observations on the minor’s progress.
  • d) Vaccination data: vaccination schedule, vaccines administered, dates of administration, upcoming scheduled vaccines and adverse reactions.
  • e) Feeding data: type of feeding (breastfeeding, formula, complementary feeding), feeding times, food preferences, dietary restrictions and intake records.
  • f) Sleep data: sleep patterns, schedules, duration, sleep quality, naps and night wakings.
  • g) Routine and activity data: daily routines, diaper changes, baths, walks, play time, early stimulation activities and medical appointments.
  • h) Any other personal data that the father, mother or legal representative voluntarily decides to enter in the free-text fields or in the files they attach.

1.3. Purposes of the Processing

  • a) Enabling the recording and tracking of the minor’s growth, development and health;
  • b) Generating reminders for medical appointments, vaccines, medications and care activities; recording and analyzing sleep, feeding and daily routine patterns;
  • c) Tracking developmental milestones (motor, cognitive, language and socio-emotional);
  • d) Facilitating quick access to health information to share with health professionals when the legal representative authorizes it;
  • e) Generating statistics and reports on the minor’s development and well-being, and personalizing the user experience according to the minor’s age and stage of development;
  • f) Generating indicators, predictions and guidance suggestions from the information recorded by the user, without these constituting a diagnosis, advice or medical recommendation; and
  • g) Anonymizing and aggregating the information processed through NomiNest to produce comparative statistics, indicators and reference metrics that allow users to be shown comparisons against aggregated and anonymous data of other users, without identifying specific persons.

The results, indicators and suggestions generated by the Application are for guidance only and in no case replace professional medical consultation.

1.4. Sensitive data

Under article 5 of Law 1581 of 2012, sensitive data are those that affect the privacy of the Data Subject or whose improper use may lead to discrimination. In the context of NomiNest, the sensitive data that may be Processed include, without limitation: data relating to the minor’s health, biometric data and photographs.

Since NomiNest may process sensitive data, and in accordance with article 6 of Law 1581 of 2012, Nanara informs the Data Subject that the following sensitive data will be Processed, together with the specific purpose of such Processing:

Sensitive dataPurpose
Identification data of the minor: name or nickname, date of birth, sex, photograph (biometric data), weeks of prematurity and relationship to the user.Personalizing the user experience and generating reminders and alerts tailored to the minor’s age.
Health data: symptoms, temperature, oxygen saturation and heart rate, medications and dose reminders, vaccines, medical appointments, laboratory tests with photo attachments (biometric data) or PDF, food allergies and intolerances, and blood type.Keeping a centralized record of the minor’s health, facilitating the tracking of medical conditions, and allowing relevant information to be shared with health professionals when the user authorizes it.
Growth and development data: weight, height, head circumference, growth curves, developmental milestones (motor, cognitive, language and socio-emotional) and observations on the minor’s progress.Monitoring the minor’s physical growth through growth curves, tracking developmental milestones according to age, identifying possible deviations that require medical attention, and generating development reports to share with pediatricians.
Sleep data: naps, night sleep, quality, night wakings and sleep training.Recording and analyzing the minor’s sleep patterns, identifying habits and trends, generating statistics on sleep quality, and providing useful information for pediatric consultations.
Feeding and hydration data: breastfeeding, bottle feeding, solids, food introduction, milk expression and milk bank, fluid intake, food preferences and dietary restrictions.Recording the minor’s eating habits, tracking the introduction of foods, identifying possible allergies or intolerances, and generating useful information for nutritional or pediatric consultations.
Routine and activity data: daily routines, diaper changes, baths, walks, play time, early stimulation activities and other care activities.Keeping a record of the minor’s daily routines, facilitating care coordination among multiple caregivers, identifying behavior patterns, and generating reminders for care activities.

It is important to note that the use of NomiNest may not be made conditional on the Data Subject providing sensitive personal data. The scope of the sensitive information collected will depend exclusively on what the father, mother or legal representative voluntarily decides to provide.

1.5. Specific retention and deletion criteria

Without prejudice to the general provisions on retention and deletion contained in the Policy, the following rules apply specifically to NomiNest:

  • a) Total deletion. When the account is deleted, the following are deleted: the user’s account (email and sign-in identifiers) and all data of the minors in their care: sleep, feeding, hygiene, growth, health, vaccines, milestones, routines, notes and photographs.
  • b) Partial deletion. Without needing to close the account, the father, mother or legal representative may request the deletion of any of the following categories, keeping their account and the rest of the information:
  • The stored photographs;
  • The records of one of the minors in their care;
  • The attached medical tests (photo or PDF files); or
  • Any other specific data that the Data Subject or their legal representative identifies in their request.

The request may be made from within the Application or by writing to dev@nanara.co from the email address associated with the account, with the subject “Delete data” (“Suprimir datos”).

The maximum response time is fifteen (15) business days, in accordance with Law 1581 of 2012.

ANNEX 1 — PERSONAL DATA PROCESSORS

This annex forms an integral part of the Privacy and Personal Data Processing Policy of NANARA S.A.S. and identifies the Data Processors in place as of the date of this Policy.

In accordance with article 25 of Decree 1377 of 2013, Nanara has entered into a personal data transmission agreement with each Processor that sets out the scope of the Processing, the activities that the Processor will carry out on behalf of Nanara and the Processor’s obligations towards the Data Subject and the Controller.

ProcessorFunctionData processed
SupabaseDatabase, authentication and file storage.All personal data recorded in the Applications, including identification data, health data, photographs, attachments and access credentials.
SentryDiagnosis of technical failures of the Applications.Technical diagnostic data from the device and the user’s session. Data of the person being cared for is excluded.
PostHogUsage analytics for the Applications.Usage events and the adult’s account identifier. Data of the person being cared for is excluded.
RevenueCatSubscription management.The user’s account identifier and subscription status.
Apple and GoogleAuthentication, push notifications and payment processing on their own platforms.Authentication data and payment transaction data. Nanara does not receive or store payment methods; processing takes place entirely on Apple’s and Google’s platforms.

The list of Data Processors is illustrative and may change. Its updated version will always be available in the Policy in force published at nanara.co/privacidad.

Nanara

Nanara S.A.S. — Bogotá, Colombia
dev@nanara.co

NomiNest

App Store Google Play Terms and conditions Privacy policy Delete your account

Site

Home About Nanara Español

© 2026 Nanara S.A.S. All rights reserved.