Legal
Privacy policy
This policy describes what happens to your data when you visit emodat.com and when you use the eMODAT® app – written specifically for this service rather than as a generic template. Sections 2 to 8 concern the website, section 9 the app and the backend; the remaining sections apply to both.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Devacon GmbH
Lessingstrasse 16
16356 Ahrensfelde
Germany
Phone: +49 30 8145332-0
Email: info_contact@devacon.eu
Managing Director: Dipl.-Ing. Eduard Meiler
2. Hosting and server logs
This website is operated on servers of IONOS SE, Elgendorfer Strasse 57, 56410 Montabaur, Germany, in a data centre located in Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with IONOS.
Each time a page is accessed, data transmitted by your browser is automatically stored in log files:
- IP address of the requesting device
- date and time of access
- address requested and volume of data transferred
- notification of whether the request was successful
- previously visited page (referrer) as well as browser and operating system details
This processing is technically necessary in order to deliver the website, ensure its stability and detect attacks. The legal basis is our legitimate interest in secure and functional operation (Art. 6(1)(f) GDPR). Logs are deleted after 14 days at the latest; they are not combined with any other data.
3. Cookies
This website uses no tracking cookies and therefore requires no consent banner. A small notice at the bottom of the screen simply informs you about the audience measurement in use. If you dismiss this notice, your browser remembers that locally (localStorage, key
cookie-note-dismissed); no data is transmitted to us in the process. This storage is technically necessary and permitted under § 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act).
4. Audience measurement with Umami
For audience measurement we use the open source software Umami . Umami is self-hosted on our own server within the European Union; no data is passed on to third parties and no transfer to a third country takes place.
Umami works without cookies and stores no personal data: no cookies are set, IP addresses are not stored, and no cross-device identifier is created. Only aggregated information is recorded, such as pages visited, the approximate source of the visit (e.g. search engine or referring website), browser and device type, and country of origin. No conclusions can be drawn about individual persons.
The legal basis is our legitimate interest in a privacy-friendly analysis of the reach of our online offering (Art. 6(1)(f) GDPR). As no cookies are set and no information is stored on or read from your device, consent under § 25 TDDDG is not required.
5. Contact and enquiry forms
On this website you can use forms to request a demo, request the free Basis edition or send us a message. We process the details you enter yourself – first and last name, company, industry, email address, telephone number and your message. A demo request additionally covers the edition you are interested in (Online or On-Premise) and the approximate number of users; the contact form covers the type of enquiry you select. The time of submission and your IP address are also recorded for technical reasons.
The IP address, a simple verification question before submission and an additional field invisible to you that only automated programs fill in serve to prevent spam submissions. The data is stored on our server in Germany referred to above and transferred into our own customer management system, likewise operated in Germany, so that your enquiry is not lost. It is used solely to handle your enquiry; it is not passed on to any third party.
The legal basis is Art. 6(1)(b) GDPR where your enquiry serves to initiate a contract, and otherwise our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR). We delete the data once your enquiry has been dealt with conclusively and no statutory retention periods apply; for business transactions the commercial and tax retention periods of six and ten years respectively apply.
If you contact us instead by email or telephone , we process the details arising – your contact details and the content of your message – for the same purposes, on the same legal bases and with the same deletion periods as described above.
6. Fonts and images
Fonts and images are loaded entirely from our own server. There is no connection to Google Fonts or any other external image service , so your IP address is not transmitted to anyone for that purpose.
For the origin of the images used on this website – including which of them were created using generative AI – please see our Image credits. In data protection terms these images are irrelevant: they show no real people.
7. Product video (YouTube)
On the home page we embed a product video hosted on YouTube (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The video is not loaded automatically. Until you click on it, you see only a preview image served from our own server – up to that point no request whatsoever is sent to Google or YouTube.
Only when you click the preview image is the player loaded. YouTube then learns your IP address as well as technical details about your browser and device, and may transfer data to the USA; an adequacy decision of the EU Commission is in place for the USA (EU-US Data Privacy Framework). We use the enhanced privacy mode (domain youtube-nocookie.com). According to Google, cookies or comparable identifiers are then set only when playback starts, not already when the player loads.
The legal basis is your consent, which you give by deliberately clicking on the video (Art. 6(1)(a) GDPR, § 25(1) TDDDG). We point out this consequence directly at the preview image. You can withdraw your consent at any time with effect for the future by reloading the page and not starting the video again. For details of what Google processes thereafter, please see Google's privacy policy at policies.google.com/privacy.
8. Links to the app stores
We link to the eMODAT® app in the Apple and Google app stores. These links are ordinary hyperlinks – as long as you do not click them, no data is transmitted to Apple or Google. Once you click, the privacy policy of the respective provider applies: Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland, and Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When you download the app, these providers process data about your account and your device under their own responsibility; we have no influence over this. What the app itself processes is described in section 9.
9. The eMODAT® application (app and backend)
A different allocation of roles applies to use of the eMODAT® application than to visiting this website. We set it out here:
eMODAT® is the product; in the App Store and on Google Play it is offered under various names – for example „eMODAT Wohnungsübergabe“. These variants are based on the same application and differ only in the range of forms supplied with them. The following information applies to all of these apps regardless of the name under which they appear in the respective store.
- The app for Android and iOS transmits what you record in it to the backend of the company using eMODAT® – and nowhere else. Data from the app reaches us in one case only: when you yourself send log files for troubleshooting (see below). No third-party analytics, advertising or tracking services are integrated into the app.
- The backend runs either on a server in our network in Germany or – in the case of an on-premise installation – on a server in the network of the company using it. It is currently not operated in any public cloud.
- The controller within the meaning of the GDPR for the data processed in the application is the company using it, not Devacon GmbH. Where we operate the backend, we act solely on behalf of that company (Art. 28 GDPR); the details and the technical and organisational measures are governed by the data processing agreement. Where the backend is located on the premises of the company using it, we have no accessto the data stored there: we maintain no permanent remote access. If, exceptionally, access to the system is required in order to provide support, the company must grant us that access expressly in the individual case; a data processing agreement applies to this as well.
- Access and erasure: If your data is processed in eMODAT® – for example as an employee or customer of a user organisation – please address your request to that company. If such a request reaches us, we forward it there without delay and do not answer it ourselves.
Where we operate the backend
If your company uses the Online edition, the backend runs on servers in Germanythat we operate. Your company remains the controller for the data stored there; we act solely on its instructions.
- Access is limited to those of our staff who keep the service running – for administration, maintenance and fault resolution. There is no access for our own purposes; your data is neither analysed nor passed on nor sold.
- Separation: The data of different customers is kept separate from one another.
- Transmission: Exchange between app and server is exclusively encrypted (TLS).
- Retention period: How long the data is retained is determined by your company. We delete nothing on our own initiative and retain nothing longer than the engagement provides for.
- After the contract ends we delete the data or return it – at your company's choice (Art. 28(3)(g) GDPR). The deadline and the form are governed by the data processing agreement.
If, by contrast, the backend is located on your company's own premises, what was said above applies: we have no access to it.
Sign-in and user account
You need a user account in order to use the app. It is issued and administered by the company using eMODAT®; your sign-in credentials are verified against that company's backend. We do not issue accounts and do not maintain any user directory of our own. Where the app is connected to a company directory (Active Directory), you sign in with the credentials held there.
Capture without a network connection and later transmission
The app is designed so that you can work even without a network connection . To that end your entries, photographs and signatures are initially stored exclusively locally on your device . They leave the device only once a connection to the backend is available again and the data is transmitted.
As long as a report has not yet been transmitted, it exists only on your device. You can delete it there; details on removing local data are given in section 14.
After a successful transmission the app removes the attachments – photographs, for example – and the recorded answers from the device automatically in the factory setting. The report itself and those fields intended for searching remain in the list of sent reports; depending on how the form is built, these may contain personal data. This automatic clean-up can be switched off in the app settings – all data then remains on the device until you delete it yourself.
Storage on your device
Everything the app stores locally is held in its own storage area, protected by the operating system, which other apps cannot access. Protection at rest relies on the encryption provided by your operating system: iOS and Android encrypt device storage provided you have set up a device lock – passcode, fingerprint or face recognition. No further encryption is applied by the app itself.
You should therefore set up a device lock if you use the app to record personal data. Without one, locally stored data is not protected if the device is lost or stolen. The company using eMODAT® should make this mandatory for the devices in use.
Photographs, signatures and attachments
Photographs, digital signatures, readings and other attachments that you add to a report are stored as part of that report and transmitted together with it to the backend of the company using the app.
A digital signature is stored exclusively as an image of the written signature . Pressure, writing speed and other dynamic characteristics of the signing process are neither recorded nor transmitted; this therefore creates no biometric data for the purpose of uniquely identifying a person.
Which fields a form contains and which evidence is collected is determined by the company using the app; it is also responsible for ensuring that there is a legal basis for the collection – for instance where people are visible in a photograph or a signature is obtained.
App permissions
The app requests only those permissions it needs in order to capture data. You can withdraw each of them individually in your device settings; the corresponding function is then no longer available.
- Camera – for photographs added to a report, barcode scanning and text recognition. For recognising barcodes and text we use the ML Kit library from Google. It is built into the app and works entirely on your device: neither the images nor the recognition results are transmitted to Google or any other provider, and no connection is made to any internet service.
- Location – exclusively for the location field, see the next section.
- Photos and files – so that existing images or attachments can be selected.
Access to the microphone, contacts and calendar is not requested.
Location data in the report
If a form contains a
location field, then when you tap that field
the latitude, longitude and time are stored as the field value in the report and transmitted with it to the backend. This happens solely in response to your deliberate input: The app does not record location automatically, continuously or in the background. If a form contains no location field, no location data is processed.
The app requests location permission solely for use while the app is open („While Using the App“) – background permission is not requested. In the app's GPS settings you can
disable location access entirely as well as set the accuracy and time limit for capture; these settings are stored only locally on your device.
Since such an entry documents a person's whereabouts at a particular time, the company using eMODAT® decides whether and in which forms this field is used. It is also responsible for informing its employees about this and for observing any applicable participation rights – a works agreement, for example.
What the app does not do
The app contains no analytics, advertising or tracking components, no service for the automatic transmission of crash reports and sends no push notifications. Analyses within the app – average processing times, for example – are calculated locally from your own reports and do not leave your device.
Logs for troubleshooting
A function in the app lets you send technical log files to our support team. This happens only if you trigger it yourself – no logs are transmitted automatically.
What is transmitted are the app's log files together with your user name, the device model, the version of the operating system and of the app, and the time of transmission. The data goes to a server of Devacon GmbH's own (mylog.emodat.com) and not to your company's backend. Access is restricted to members of our support team.
On receipt, our support team is notified with a retrieval link that expires after 14 days . We delete the logs no later than 90 days after receipt. The legal basis is our legitimate interest in resolving faults (Art. 6(1)(f) GDPR); for this transmission we are the controller in our own right.
10. Recipients of your data
- IONOS SE – hosting, processor pursuant to Art. 28 GDPR
- Google Ireland Limited (YouTube) – product video, only after you click the preview image
When you use the application, the data you record goes to the company using eMODAT® – the details and the allocation of roles are set out in section 9.
Beyond this we do not pass your data on. Data is never sold.
11. Retention periods
We store personal data only for as long as is necessary for the respective purpose or as required by statutory retention periods. In detail:
- Server logs: deleted after 14 days at the latest.
- Enquiries submitted through the forms (contact, demo, Basis edition): deleted once the enquiry has been dealt with conclusively and no retention period applies – as a rule no later than six months after the last correspondence.
- Data from a contract or from free use in a business context: retained in accordance with the commercial and tax retention periods of six years (§ 257 HGB) and ten years (§ 147 AO) respectively, calculated from the end of the relevant calendar year. During this time processing is restricted to fulfilling those obligations.
- Audience measurement (Umami): no personal data arises; the aggregated analyses contain no personal reference.
- Data in the eMODAT® application, where we operate the backend: the retention period is determined by the company using it as controller. We process this data only on its instructions and delete it or return it once the processing relationship ends (Art. 28(3)(g) GDPR); the details are governed by the data processing agreement.
- App log filesthat you have actively sent us for troubleshooting: deleted no later than 90 days after receipt; the retrieval link for our support team expires after 14 days.
- Dismissal of the notice in your browser (localStorage
cookie-note-dismissed): remains on your device until you clear your browser data; nothing about it is stored with us.
Where the period cannot be determined in advance in an individual case, it is governed by how long the data is needed for the stated purpose. Once it expires, the data is deleted or anonymised.
12. Data security
We take technical and organisational measures to protect your data against loss, alteration and unauthorised access.
The connection to this website is encrypted throughout
(TLS). If you call up the page without encryption, we redirect you automatically to the secure address; unencrypted use is not possible. Everything you enter into a form is likewise transmitted exclusively over this encrypted connection. You can recognise this by the address beginning with
https:// , and by the padlock symbol in your browser.
Our measures reflect the state of the art and are adapted on an ongoing basis.
13. Your rights
You have the following rights in relation to us regarding your personal data:
- access to the data stored (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
Right to object under Art. 21 GDPR
You have the right to object to the processing of your personal data. Where we process data on the basis of a legitimate interest (Art. 6(1)(f) GDPR), you may object to that processing on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
An objection is not subject to any particular form. A message to the postal or email address given in section 1 is sufficient.
14. Erasure of your data
Data in the application. Form data and user accounts are processed on the server of the company using eMODAT®. That company is the controller – please therefore address erasure requests to it. If such a request reaches us, we forward it without delay.
Log files. Logs you have sent us via the „Send log file“ function are deleted automatically no later than 90 days after receipt. You can request earlier erasure at any time, without any particular form, at support@devacon.eu .
Data on your device. You remove locally stored data – such as reports not yet transmitted and your app settings – by deleting the app from your device.
Data from this website. We delete enquiries submitted through our forms in accordance with the periods stated in section 11. You can also request erasure earlier using the contact details given in section 1.
15. Right to lodge a complaint with the supervisory authority
You can lodge a complaint with a data protection supervisory authority at any time. The authority responsible for us is:
Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg (Data Protection Commissioner for the State of Brandenburg)
Stahnsdorfer Damm 77
14532 Kleinmachnow, Germany
www.lda.brandenburg.de
16. No automated decision-making
Automated decision-making, including profiling, within the meaning of Art. 22 GDPR does not take place.
17. Obligation to provide data
You can use this website without providing any personal data. If you wish to contact us through a form, we need at least your name and a means of contacting you – without these details we cannot answer your enquiry. There is no statutory or contractual obligation to provide data.
18. Changes to this policy
We update this policy whenever the technology in use or the legal position changes. The version published here, bearing the date given below, is the applicable one.
Last updated: 2 September 2026
