Processing of personal data

Privacy policy

This policy describes what the application processes and what this web site processes. The two are set out separately because they happen separately.

Controller

The controller within the meaning of Art. 4(7) GDPR is the provider named in the legal notice. The address and contact details are there and are not repeated here. Data protection enquiries to support@armamentarium.app or through the contact form.

The application

What stays on the device

Army lists, the collection and the settings live solely in a database on the device. Photos added to the collection do not leave the device. There are no accounts, no sign-in, no telemetry, no advertising and no analytics services.

The application reaches the network in two places. Both happen at the user's instigation; neither runs in the background.

1 Catalogue download

Purpose

Obtaining public rules catalogues from public GitHub repositories of the BSData community, on an explicit request made in the application.

Transmitted

No personal data. The connection itself is made to the operator of the repository; their terms apply to that retrieval.

Legal basis

Art. 6(1)(b) GDPR — carrying out the function that was requested.

2 Error report

Purpose

Fixing reported faults. The report is written in the settings by the user and sent by the user.

Transmitted

Solely the text that was entered and — only where the box is ticked — the program log.

Redaction of the log

Before sending, the user name, personal folder paths and the names of army lists are removed from the log.

No sender

No sender is transmitted; there is no field for a reply address and there will not be one. An error report therefore cannot be answered.

Legal basis

Art. 6(1)(f) GDPR — legitimate interest in a working application.

This web site

Access data

When this page is retrieved, the provider of the server infrastructure processes technically necessary access data. The purpose is delivery and operational security. The legal basis is Art. 6(1)(f) GDPR.

Processor

The site runs on a virtual server operated by IONOS SE, Montabaur. The processing is carried out under a data processing agreement pursuant to Art. 28 GDPR.

No third-party services

No audience measurement, no analytics, no consent banner. Fonts, icons and images are served from the same server; no resource is loaded from a foreign host.

One single cookie, and it is technically necessary: the two pages carrying the contact form set one that protects the submission against forgery. It holds no identifier of the person, ends with the browser session, and requires no consent under § 25(2) TDDDG. Every other page of this site sets none.

The contact form

Fields and recipient

Two details are transmitted: the email address that was entered and the message. No name, no subject. They are sent as an email to the provider; delivery runs through the same host that serves the site.

Purpose, legal basis, retention

The purpose is handling the enquiry. The legal basis is Art. 6(1)(f) GDPR, or (b) for pre-contractual enquiries. The details are kept until the enquiry has been dealt with and are deleted afterwards; statutory retention obligations remain unaffected.

Voluntary

Giving an address is not required — there is no obligation to use the form at all. Without one, however, no reply is possible.

Spam protection

The form checks a hidden field and a minimum time between opening and sending. Both run on the same server; no third-party captcha is used.

The purchase

The unlock is handled solely through the respective distribution channel. Payment data does not reach the provider, who learns neither the means of payment nor the buyer's address. The terms of the operator of the distribution channel apply to the transaction. The price and the contracting party are under Legal.

Rights of the data subject

Rights of the data subject and where they are found in the GDPR
Right Article
Access to the data processedArt. 15
Rectification of inaccurate dataArt. 16
ErasureArt. 17
Restriction of processingArt. 18
Data portabilityArt. 20
Objection to processingArt. 21

Right to lodge a complaint

Independently of the above, there is a right to lodge a complaint with a supervisory authority under Art. 77 GDPR. The competent authority is the data protection supervisory authority of Baden-Württemberg.