Privacy Policy — myJikita
Draft — last updated: September 2026
This policy is a complete working draft written from the application as built. It has not yet been reviewed or approved by counsel or a DPO. The retention periods, the sub-processor list and the legal basis for disclosure to rescue services are all marked below and must be confirmed before publication or store submission. The controller's identity in section 1 is taken from the public register and is not a draft.
If you want the plain-language version rather than the formal one, read What data myJikita holds and Who can see your position instead. They describe the same thing in ordinary words.
1. Who we are
myJikita is published by DATALPS, a French société par actions simplifiée (SAS) with a share capital of €10,000, which operates the Alpik products.
| Registered office | 6 C chemin des Cavaliers, 73100 Tresserve, France |
| Registration | 929 143 634 R.C.S. Chambéry |
| SIREN | 929 143 634 |
| SIRET (registered office) | 929 143 634 00012 |
| Intra-community VAT | FR17929143634 |
For everything covered by this policy, DATALPS is the data controller.
Data protection contact: privacy@alpik.fr General support: contact@alpik.fr
2. What this policy covers
The myJikita mobile application for iOS and Android, the Alpik services behind it, and the Jikita tags the app works with.
The other Alpik products have their own policies: Alpik Pro and Alpik Forwarder.
3. What we process
Account data
| Data | Why |
|---|---|
| Name | Identifying you to the contacts you share with, and to rescue services in an emergency |
| Email address | Authentication, account and security notifications |
| Account identifier | Linking your data to your account |
Authentication is handled by Alpik's own identity service. We never receive your password: you type it into the identity service in your phone's browser, not into the application.
Location data
This is the core of the service and the most sensitive category we hold.
| Data | Why |
|---|---|
| Position (latitude, longitude), with accuracy and timestamp | The purpose of the service: sharing your position with the contacts you choose, and making you findable in an emergency |
| Whether the device had network connectivity at that position | Identifying coverage gaps, so silence can be interpreted correctly and shown back to you |
| Time a position was captured, and time it was received | Distinguishing a delayed batch from current movement — operationally critical during a search |
Positions are recorded only while you have deliberately started an outing. There is no background collection between outings.
Outing data
Activity, place, expected return time, planned route (GPX), party composition, start and stop times, off-route state, and whether an SOS was raised.
Contacts and sharing
The contacts you create inside myJikita, their invitation status, and which contacts each outing was shared with.
We do not access, read or upload your phone's address book.
Messages
The content and timestamps of messages exchanged in an outing conversation, between the outing's owner and the contacts it was shared with.
Jikita tag data
| Data | Why |
|---|---|
| Tags registered to your account: identifier, name, battery, last seen | Managing your own tags |
| Sightings of any tag heard by your device — the tag's own signed broadcast, signal strength and time heard | Locating tags, including tags belonging to other people, in areas without mobile coverage. See Who can see your position |
A sighting concerns the tag that was heard, not the phone that heard it.
Device and technical data
Device model and operating system version; the device identifier used to enforce one active device per account; push notification tokens; connection metadata (IP address, timestamps); error and diagnostic logs.
What we do not process
Your phone's address book. Your photos or camera. Your microphone. Your browsing history. Your health data. Advertising identifiers. We run no advertising and no third-party analytics or tracking in the application.
4. Purposes and legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the application: account, outings, position sharing, messaging, maps | Contract performance — Art. 6(1)(b) |
| Sharing your position with the contacts you selected | Contract performance — Art. 6(1)(b) |
| Sending notifications about outings, messages, overdue status and SOS | Contract performance — Art. 6(1)(b) |
| Making data available to rescue services in an emergency | Vital interests — Art. 6(1)(d), and legal obligation Art. 6(1)(c) where applicable |
| Relaying sightings of Jikita tags, including tags not registered to you | Vital interests — Art. 6(1)(d) — and legitimate interest Art. 6(1)(f): enabling a person in distress to be located |
| Enforcing one active device per account; detecting abuse; keeping the service secure | Legitimate interest — Art. 6(1)(f) |
| Diagnosing faults and improving reliability | Legitimate interest — Art. 6(1)(f) |
| Complying with legal obligations | Legal obligation — Art. 6(1)(c) |
5. Data retention
| Category | Proposed retention |
|---|---|
| Account data | For as long as the account exists, then 30 days |
| Positions and tracks | 12 months from capture |
| Outing metadata (plan, route, SOS) | 12 months |
| Outing messages | 12 months |
| Contacts and sharing relationships | Until deleted by you, or account closure |
| Jikita tag sightings | 12 months |
| Push tokens | Until the device is revoked or the app removed |
| Technical and security logs | 12 months |
| Records of disclosure to rescue services | For as long as the account exists, then 30 days |
Data associated with an active search may be retained longer where it is needed for that operation or for any subsequent proceedings.
After the applicable period, data is deleted or irreversibly anonymised.
On your own device: signing out erases the outings, tracks, contacts and messages stored on the phone. Downloaded map areas are kept, because they contain no personal data.
6. Who we share with
The contacts you choose
The people you select for an outing see your position, your plan and your messages while that outing is running. You choose them, per outing, and stopping the outing ends it.
Rescue services
In an emergency, data relevant to locating a person may be made available to authorised rescue organisations through a dedicated rescue console.
Rescue organisations are set up by us as organisations in the console, with named, authenticated operators. Access is not granted ad hoc during an incident.
A rescue service may search for a person. A search returns whether they are a user and, where an outing is running, its name, its date, the expected return time, and whether an SOS has been raised.
A search is not notified to the person searched for. Its purpose is to establish which person a call concerns — eliminating people who share a name, have no outing shared, or have no connection to the caller — before any record is opened. It returns nothing about where anyone is, and it exists so that fewer full records have to be accessed. The reasoning is set out in Who can see your position.
If a service then accesses a profile, position or any other information, the person is notified by email at the moment of access, and that email gives the contact details of the rescue service's own Data Protection Officer. No further email is sent for 24 hours however many actions follow; if the access is still going on after 24 hours, a further email is sent, and again every 24 hours while it continues. Notification is never deferred or suppressed.
Every action is logged with its time, its nature and the operator who performed it. That log is available to the rescue service's DPO so they can answer the person's questions, and it is kept for the lifetime of the account.
A rescue service that decides for itself what to do with the data it accesses is a separate controller for that processing, not our processor, and answers for it under its own obligations.
The full description, and the legal basis, are in Who can see your position.
Sub-processors
| Processor | Role | Location |
|---|---|---|
| Scaleway SAS | Cloud hosting and infrastructure | EU (France) |
| Google Ireland Ltd. | Push notification delivery to Android devices (Firebase Cloud Messaging) | EU / US under an adequacy framework |
| Apple Distribution International | Push notification delivery to iOS devices (APNs) | EU / US under an adequacy framework |
Push notifications are delivered through the platform services above. The notification content is kept minimal, and the application never treats the content of a push as authoritative data.
We do not sell your data, and we do not share it for advertising or marketing purposes.
Legal requests
We may disclose data where required by law, by a court, or by a competent authority.
7. International transfers
Your data is hosted and processed in the European Union. The only routine exception is push notification delivery, which necessarily passes through Apple and Google infrastructure.
8. Security
- All communication between the application and our services uses encrypted connections (TLS).
- Authentication credentials are held in the phone's secure storage.
- One device at a time may be active on an account, and you can revoke a device at any time.
- Access to production data is restricted to authorised personnel.
- Jikita tag broadcasts are cryptographically signed by the tag and verified server-side, so a sighting cannot be forged by the phone that submits it.
Messages are not end-to-end encrypted. They are carried over encrypted connections and stored on our servers, which is what allows delivery to a phone that was offline. Treat an outing conversation as a safety channel, not a private one.
9. Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction, portability, and objection (Art. 15–21), and the right to withdraw consent where processing is based on it.
How to exercise each of these in practice is in Your rights over your data.
Access and erasure are available in the app, under Settings → Your data, and require no request to us: see What do you know about me and Delete your account and your data.
To exercise any other right, or if you cannot use the app: privacy@alpik.fr.
You may also lodge a complaint with the French data protection authority, the CNIL: https://www.cnil.fr — or with the supervisory authority in your own country.
10. Changes to this policy
We will update this policy when the application changes. Material changes will be brought to your attention in the application. The date at the top of this page always reflects the current version.
11. Contact
Data protection: privacy@alpik.fr Support: contact@alpik.fr