App Privacy Policy
1. Introduction
This Privacy Policy explains how ConPDS ApS ("ConPDS", "we", "us", or "our") collects, uses, stores, and protects personal data when you use the ConPDS Checker mobile application for Android and iOS (the "App"). The App is a commercial product provided as part of a subscription-based service for container inspection photo documentation.
By installing and using the App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with these practices, please do not use the App.
Capitalised terms not defined in this Privacy Policy have the meanings given in our Terms & Conditions.
2. Data Controller
The data controller responsible for the processing of your personal data is:
- ConPDS ApS
- Lille Gedved 6, 8700 Horsens, Denmark
- VAT No. DK35828192
- Email: info@conpds.com
- Phone: +45 60 40 70 00
3. App Permissions
Upon first launch, the App requests the following device permissions:
- Camera (required): To capture photos and videos of containers during inspections.
- Storage (required): To save encrypted media files locally on the device before upload.
- Microphone (optional): To record audio notes or capture video with sound, if enabled.
- Location (optional): To tag media with GPS coordinates for geolocation reference, if enabled.
You may decline optional permissions without affecting core functionality. Required permissions are necessary for the App to operate.
4. Data We Collect
The App collects the following categories of data:
- Photos and videos: Images and video clips captured during container inspections.
- Container numbers: Recognised via on-device optical character recognition (OCR) from captured images.
- GPS coordinates: If location services are enabled, the geographic position where media is captured.
- Timestamps: Date and time of each capture event.
- Device information: Device model, operating system version, app version, and Internet Protocol (IP) address.
- Account credentials: The Customer PIN used to authorise the device against a ConPDS tenant.
- Email addresses: Addresses entered by the Customer or stored in the system Address Book for automated photo delivery.
5. How We Use Your Data
We process personal data for the following purposes:
- Service delivery: Providing the ConPDS Checker inspection documentation service, including photo capture, upload, storage, and retrieval.
- Container number recognition: On-device and server-side OCR processing to identify container numbers from images.
- Automated photo delivery: Sending inspection photos to customer-designated recipients via email or API integration.
- Service improvement: Using anonymised and aggregated data, including images, to improve our services and enhance the performance of our OCR engine.
- Account management: Account creation, device authorisation, login credential delivery, password recovery, and system communications.
- Error diagnostics: Collecting log data in the event of app errors to identify and resolve technical issues.
6. Legal Basis for Processing (GDPR)
We process personal data on the following legal bases under the General Data Protection Regulation (GDPR):
- Performance of a contract (Art. 6(1)(b)): Processing necessary to provide the ConPDS Checker service under the subscription agreement between ConPDS and the Customer.
- Legitimate interest (Art. 6(1)(f)): Processing anonymised and aggregated data for service improvement and OCR engine training. Our legitimate interest is maintaining and improving the quality of our products. This processing does not override your rights, as data used for training is anonymised.
- Consent (Art. 6(1)(a)): Where applicable, such as for optional location data collection. You may withdraw consent at any time by disabling the relevant permission in your device settings.
7. On-Device Data Handling
Captured photos and videos are encrypted and stored securely on the device's local storage. This encryption protects data in the event the device is lost or compromised.
The App retains encrypted local copies of media files for fourteen (14) days after successful upload to the ConPDS platform. After this retention period, local copies are automatically and permanently purged from the device. This temporary retention provides a backup in case of connectivity issues requiring re-upload.
8. Data Upload and Transmission
Before uploading, the App decrypts media files on the device. Decrypted data is transmitted to the ConPDS platform via a secure SSL/TLS connection (HTTPS), ensuring encryption in transit. The platform sends a confirmation receipt upon successful upload.
Data is only uploaded when an active network connection is available. The App does not transmit data in the background without user initiation.
9. Server-Side Processing and Storage
All customer data is stored exclusively in secure data centres located within the European Union, in compliance with EU data sovereignty and protection regulations. Uploaded media and metadata (container numbers, timestamps, GPS coordinates, user information) are stored in a secure database and indexed for efficient retrieval and management.
10. Data Sharing and Third Parties
We do not sell, rent, or trade your personal data to third parties. Data is shared only in the following circumstances:
- Automated photo delivery: Inspection photos may be delivered to recipients designated by the Customer (e.g., shipping lines, depot operators) via email or API, as configured by the Customer.
- Google Play Services (Android): The Android version of the App uses Google Play Services, which may collect certain device and usage information as described in Google's privacy policy.
- Cloud infrastructure providers: ConPDS uses EU-based cloud infrastructure providers to host and process data. These providers act as sub-processors under appropriate data processing agreements.
The App does not contain advertising SDKs. No advertising networks receive data from the App.
11. Data Retention and Deletion
- On-device: Encrypted media copies are retained for 14 days after upload, then automatically purged.
- Server-side (active subscription): Customer data is retained for the duration of the subscription.
- Server-side (after termination): Upon termination of the subscription, customer data is retained for a grace period of thirty (30) days, during which the Customer may extract their data. After this period, ConPDS permanently deletes all customer data unless otherwise required by applicable law.
- Training data: Anonymised and aggregated data used for OCR engine training is retained indefinitely, as it cannot be linked back to individual users or customers.
12. Account and Data Deletion
You may request deletion of your account and all associated personal data at any time by:
- Contacting us at info@conpds.com; or
- Requesting deletion through the ConPDS Checker web dashboard (if available to your account).
Upon receiving a valid deletion request, we will process it within thirty (30) days. We will confirm deletion in writing once complete. Deletion does not extend to anonymised data that can no longer be linked to you, nor to data that we are required to retain by applicable law.
13. Your Rights Under GDPR
If you are located in the European Economic Area (EEA), you have the following rights regarding your personal data:
- Right of access (Art. 15): You may request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): You may request that we correct inaccurate or incomplete personal data.
- Right to erasure (Art. 17): You may request that we delete your personal data, subject to legal retention obligations.
- Right to restriction (Art. 18): You may request that we restrict the processing of your personal data under certain circumstances.
- Right to data portability (Art. 20): You may request a machine-readable copy of the personal data you provided to us.
- Right to object (Art. 21): You may object to processing based on legitimate interest. We will cease processing unless we demonstrate compelling legitimate grounds.
To exercise any of these rights, contact us at info@conpds.com. We will respond within thirty (30) days.
You also have the right to lodge a complaint with a supervisory authority. The relevant authority in Denmark is the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark — www.datatilsynet.dk.
14. Data Tracking
The App does not track users across third-party apps or websites. We do not collect advertising identifiers (such as IDFA or GAID) and do not share data with advertising networks or data brokers.
15. Cookies
The App does not use cookies. If you access the ConPDS web dashboard through a browser, functional cookies may be used as described in the cookie preferences available on the website.
16. Children's Privacy
The App is not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If we discover that a child under 16 has provided us with personal data, we will take steps to delete it promptly. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at info@conpds.com.
17. Security
We employ commercially reasonable security measures to protect your personal data, including:
- Encryption of media files at rest on the device;
- SSL/TLS encryption for all data in transit;
- Access controls and authentication for server-side systems;
- Regular backups to ensure data recoverability;
- EU-only data centre hosting with physical and logical security controls.
No method of electronic storage or transmission is 100% secure. While we strive to protect your personal data, we cannot guarantee its absolute security.
18. Links to Other Sites
The App may contain links to third-party websites or services. These external sites are not operated by us. We strongly advise you to review the privacy policies of any third-party sites you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
19. International Data Transfers
All personal data collected through the App is stored and processed exclusively within the European Union. ConPDS does not transfer personal data outside the EU/EEA.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised effective date, and where practicable, by notification within the App or via email. Continued use of the App after such changes constitutes your acceptance of the updated Privacy Policy.
21. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
- Email: info@conpds.com
- Phone: +45 60 40 70 00
- Address: Lille Gedved 6, 8700 Horsens, Denmark