Processing of personal data
Privacy policy
This policy describes what the application processes and what this web site processes. The two are set out separately because they happen separately.
Controller
The controller within the meaning of Art. 4(7) GDPR is the provider named in the legal notice. The address and contact details are there and are not repeated here. Data protection enquiries to support@armamentarium.app or through the contact form.
The application
What stays on the device
Army lists, the collection and the settings live solely in a database on the device. Photos added to the collection do not leave the device. There are no accounts, no sign-in, no telemetry, no advertising and no analytics services.
The application reaches the network in two places. Both happen at the user's instigation; neither runs in the background.
1 Catalogue download
Purpose
Obtaining public rules catalogues from public GitHub repositories of the BSData community, on an explicit request made in the application.
Transmitted
No personal data. The connection itself is made to the operator of the repository; their terms apply to that retrieval.
Legal basis
Art. 6(1)(b) GDPR — carrying out the function that was requested.
2 Error report
Purpose
Fixing reported faults. The report is written in the settings by the user and sent by the user.
Transmitted
Solely the text that was entered and — only where the box is ticked — the program log.
Redaction of the log
Before sending, the user name, personal folder paths and the names of army lists are removed from the log.
No sender
No sender is transmitted; there is no field for a reply address and there will not be one. An error report therefore cannot be answered.
Legal basis
Art. 6(1)(f) GDPR — legitimate interest in a working application.
This web site
Access data
When this page is retrieved, the provider of the server infrastructure processes technically necessary access data. The purpose is delivery and operational security. The legal basis is Art. 6(1)(f) GDPR.
Processor
The site runs on a virtual server operated by IONOS SE, Montabaur. The processing is carried out under a data processing agreement pursuant to Art. 28 GDPR.
No third-party services
No audience measurement, no analytics, no consent banner. Fonts, icons and images are served from the same server; no resource is loaded from a foreign host.
One single cookie, and it is technically necessary: the two pages carrying the contact form set one that protects the submission against forgery. It holds no identifier of the person, ends with the browser session, and requires no consent under § 25(2) TDDDG. Every other page of this site sets none.
The contact form
Fields and recipient
Two details are transmitted: the email address that was entered and the message. No name, no subject. They are sent as an email to the provider; delivery runs through the same host that serves the site.
Purpose, legal basis, retention
The purpose is handling the enquiry. The legal basis is Art. 6(1)(f) GDPR, or (b) for pre-contractual enquiries. The details are kept until the enquiry has been dealt with and are deleted afterwards; statutory retention obligations remain unaffected.
Voluntary
Giving an address is not required — there is no obligation to use the form at all. Without one, however, no reply is possible.
Spam protection
The form checks a hidden field and a minimum time between opening and sending. Both run on the same server; no third-party captcha is used.
The purchase
The unlock is handled solely through the respective distribution channel. Payment data does not reach the provider, who learns neither the means of payment nor the buyer's address. The terms of the operator of the distribution channel apply to the transaction. The price and the contracting party are under Legal.
Rights of the data subject
| Right | Article |
|---|---|
| Access to the data processed | Art. 15 |
| Rectification of inaccurate data | Art. 16 |
| Erasure | Art. 17 |
| Restriction of processing | Art. 18 |
| Data portability | Art. 20 |
| Objection to processing | Art. 21 |
Right to lodge a complaint
Independently of the above, there is a right to lodge a complaint with a supervisory authority under Art. 77 GDPR. The competent authority is the data protection supervisory authority of Baden-Württemberg.