Privacy Policy
Last updated: 15 Feb 2026
This Privacy Policy explains how Display Group LTD ("MMENTO", "we", "us", or "our"), operating under the MMENTO™ brand and registered under company number 16102028, collects, uses, stores, and protects personal data in connection with the website mmentoapp.com (the "Website"), the MMENTO mobile application (the "App"), and related services (collectively, the "Services").
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Spanish Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights ("LOPDGDD"), and applicable consumer protection rules.
1. Data Controller
The data controller responsible for the processing of personal data is:
- Operator: Display Group LTD
- Company number: 16102028
- Trading name: MMENTO™
- Privacy contact: our contact form
2. Categories of Data We Collect
2.1 On the Website
The Website is informational in nature. It may collect:
- Browsing data, through cookies and similar technologies, where you have given consent (see our Cookie Policy).
- Form data, when you voluntarily submit a contact form, waitlist form, or similar inquiry. This typically includes your name, email address, and the content of your message.
2.2 In the App
When you create an account and use the App, we may process:
- Account data: name, email address, password (stored in hashed form), and where applicable identifiers from third-party sign-in providers.
- Profile data: profile photo, language preference, and approximate location, where you choose to provide them.
- Subscription data: confirmation of an active subscription, transmitted by the relevant mobile application store. Payment card data is never received or stored by MMENTO; payments are handled by the application store and its payment processor.
- User Content: the notes, descriptions, ideas, images, videos, and other materials that you create or upload to your private repertory. This content belongs to you.
- Technical data: device type, operating system version, App version, language, and similar diagnostic information necessary for the Services to function and for security.
3. Purposes and Legal Bases
We process personal data for the following purposes, on the indicated legal bases under Article 6 GDPR:
- To provide the Services (account creation, authentication, hosting of User Content, delivery of features). Legal basis: performance of a contract.
- To process subscriptions and refunds. Legal basis: performance of a contract.
- To respond to inquiries submitted through forms or by email. Legal basis: legitimate interest in responding to communications, or performance of a pre-contractual request.
- To ensure the security and integrity of the Services, including fraud prevention and abuse investigation. Legal basis: legitimate interest in protecting the Services and our users.
- To comply with legal obligations, such as responding to lawful requests from competent authorities. Legal basis: compliance with a legal obligation.
- To analyse Website traffic and improve the Website, through analytics and measurement tools. Legal basis: your consent, expressed through the cookie banner.
4. How We Treat Your User Content
User Content stored within the App is treated with particular care and forms the most sensitive category of data we handle. We make the following commitments:
- We do not sell User Content.
- We do not use User Content to train artificial intelligence models, whether developed by us or by third parties.
- We do not access User Content for analytical, marketing, or commercial purposes.
- We only access User Content under the limited circumstances described below.
User Content is stored in a logically isolated database, encrypted at rest and in transit, and protected by access controls that restrict it to authorised systems necessary to provide the Services to you.
For a more detailed explanation of our approach, please consult the Transparency section dedicated to MMENTO App.
Limited Access Conditions
User Content may only be accessed in the following circumstances:
- (a) When required by a binding legal request from a competent authority.
- (b) When you expressly request technical support that cannot be resolved without such access, and only for the duration strictly necessary.
- (c) When investigating a credible incident of abuse, fraud, or security threat affecting the integrity of the Services or the safety of users.
5. Recipients of the Data
We do not sell, rent, or trade personal data. We engage trusted service providers who assist us in operating the Services. These providers act as data processors on our behalf, under written contracts that comply with Article 28 GDPR.
For privacy and security reasons, we describe these providers by category rather than by name. The following categories of processors may process personal data on our behalf:
- Hosting and database providers located within the European Union, used to store account data and User Content.
- Content delivery and media storage providers, used to deliver images, videos, and other media required for the Services to function.
- Payment platforms of the relevant mobile application stores, used solely to process subscription transactions.
- Authentication providers of the third-party sign-in services that you choose to use.
- Web analytics and audience measurement providers for the Website (see Cookie Policy).
An up-to-date list of our processors and the categories of data they handle can be requested at our contact form.
6. International Data Transfers
Personal data related to your account and User Content is primarily stored on infrastructure located within the European Union.
Some service providers may operate from, or transmit data to, countries outside the European Economic Area (in particular the United States). When this occurs, we rely on adequate transfer mechanisms permitted by the GDPR, including the European Commission's Standard Contractual Clauses, supplementary safeguards, and adequacy decisions where applicable.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:
- Account and User Content: for as long as your account remains active.
- After account deletion: User Content is deleted from active production systems following the deletion request. Residual copies may persist in encrypted backups for a maximum of thirty (30) days, after which they are automatically purged.
- Form submissions: retained for the time necessary to handle the inquiry and a reasonable additional period for legitimate follow-up.
- Billing and tax records: retained for the period required by applicable accounting and tax law.
- Security and incident logs: retained for a limited period for security purposes.
8. Your Rights
In accordance with the GDPR and the LOPDGDD, you have the following rights regarding your personal data:
- Right of access to the personal data we hold about you.
- Right to rectification of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"), subject to legal exceptions.
- Right to restriction of processing in certain circumstances.
- Right to data portability, where technically feasible.
- Right to object to processing based on legitimate interests.
- Right to withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact our contact form. We may request information necessary to verify your identity before responding.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es) or the supervisory authority in your country of residence.
9. Security
We apply technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encryption at rest and in transit, access controls based on the principle of least privilege, regular security reviews, and ongoing monitoring.
No system can guarantee absolute security. We commit to investigating and notifying users and the relevant authorities of any personal data breach in accordance with Articles 33 and 34 GDPR.
10. Minors
The Services are not directed at persons under the age of sixteen (16). We do not knowingly process the personal data of minors below this age. If we become aware that we have collected personal data from a minor below the applicable age threshold without verified parental consent, we will delete the data without undue delay.
11. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the App, the Website, or via email. The "Last updated" date at the top of this document indicates the date of the most recent revision.
12. Contact
For questions related to this Privacy Policy or to exercise your rights: