Privacy Policy for jrob GmbH Apps

Apps: Image Snap and Image Diary

Introduction and Data Controller

Protecting your personal data is our highest priority. As the data controller under the General Data Protection Regulation (GDPR), we use this privacy policy to comprehensively inform you about how we collect, process, and use personal data in our applications. jrob GmbH operates an innovative data marketplace for the exchange of vehicle recordings, which is primarily realized through our Image Snap App and Image Diary App. This platform enables users to record, store, and optionally share video recordings from road traffic with authorized recipients. We place great importance on ensuring that you retain full control over your data at all times and can transparently understand how your information is being used.

Scope of Data Collection and Legal Basis for Processing

Within the scope of using our apps, various types of personal data are collected and processed. Data collection only occurs to the extent necessary to provide the functionality of our apps or to fulfill legal obligations. The data collected includes, in particular, camera and video recordings from traffic situations or smart city environments that are created while using the Dash-Cam App. These recordings may capture vehicles, traffic situations, road layouts, and possibly also persons or license plates. Furthermore, we collect location data that is generated during active use of the app to enable precise assignment of recordings and to provide location-based services. Device information such as model designation, operating system version, and technical specifications of your smartphone or tablet are collected to ensure compatibility and optimal functionality of the apps. For technical purposes such as uploads, troubleshooting, and provision of our services, your IP address is processed. Should you voluntarily contact us, for example through support requests or feedback forms, the contact information you provide such as email address and name will be stored and processed.

The legal basis for processing your personal data derives from various provisions of the General Data Protection Regulation. According to Article 6(1)(a) GDPR, processing is based on your explicit consent, which you can revoke at any time. Insofar as data processing is necessary for the fulfillment of a contract or for the implementation of pre-contractual measures, we rely on Article 6(1)(b) GDPR. In certain cases, processing may also be based on our legitimate interest according to Article 6(1)(f) GDPR, such as to ensure IT security, to improve our services, or to detect and prevent abuse. In doing so, we always ensure that your interests, fundamental rights, and freedoms do not override our interests.

Functionality of the Data Marketplace and User Controls

Our apps form the technical foundation for a data marketplace where vehicle recordings can be exchanged between different parties. The central concept is based on you, as a user of the Dash-Cam App, creating video recordings during your journeys, which can subsequently be requested by authorized recipients. These recipients may include insurance companies, municipalities, authorities, or other legitimate institutions that have a justified interest in the recordings, for example for accident investigation, traffic planning, or for improving artificial intelligence systems in the field of autonomous driving. However, it is extremely important to us to emphasize that you, as a user, retain complete control over your data at all times and decide for yourself how your recordings are handled.

Specifically, this means that in the settings of the Dash-Cam App, you can configure both the local storage duration of your recordings and the authorization for sharing with third parties on a user-specific basis. You have the ability to determine how long recordings should remain stored locally on your device before they are automatically deleted. This can be a period ranging from a few hours to several weeks, entirely according to your individual needs and the available storage capacity of your device. Likewise, you can control in detail whether and under what conditions your recordings should be released for the data marketplace. You can completely disable the sharing of recordings, so that your videos remain exclusively local on your device and are never shared with third parties. Alternatively, you can selectively determine for which types of recipients or for which specific purposes you wish to grant authorization. This granular control ensures that you remain sovereign over your data at all times and that no unwanted sharing takes place.

Purposes of Use and Data Processing

The data collected by our apps serves various specific purposes, each tied to the functionality of the respective application. In the Dash-Cam App, the recording, storage, and playback of image and video material primarily serves to document traffic situations. These recordings can serve as evidence in traffic accidents, for personal security, or simply as a reminder of routes traveled. If you decide to share your recordings via the data marketplace, this image and video data is made available to authorized business partners. These may include insurance companies that use the recordings for claims settlement and accident reconstruction, authorities that access the data for investigative purposes or traffic safety analyses, or municipalities and research institutions that analyze traffic flows and develop smart city concepts. Furthermore, the anonymized or pseudonymized recordings can be used for training artificial intelligence, particularly for improving systems for object recognition, autonomous driving, and traffic forecasting.

The analysis and further development of our app features also takes place based on the collected data. However, in this case, generally not personal video content but aggregated and anonymized usage data is used to optimize user experience, identify technical errors, and develop new features. All processing operations are subject to strict technical and organizational measures that ensure your data is only used for the stated purposes and that the highest level of data protection is guaranteed.

Sharing of Data with Third Parties

Your personal data is fundamentally not shared with or sold to unauthorized third parties. We treat all collected information confidentially and only pass it on to other entities under certain clearly defined circumstances. Sharing occurs first with service providers who act on our behalf and support us in providing our services. These include, for example, hosting providers that operate our servers, cloud services that ensure secure storage of data, and IT service providers that assist us with maintenance and further development of the apps. These service providers are contractually obligated to comply with data protection regulations and may only process the data exclusively according to our instructions and for the agreed purposes. They are not authorized to use the data for their own purposes or to pass it on to further third parties.

Furthermore, sharing of your data with authorized business partners may occur if you have given your explicit consent to this. As already described, these may be insurance companies, municipalities, government authorities, or other organizations that have a legitimate need for the recordings. In this case, sharing occurs exclusively on the basis of your active consent and only to the extent that you have authorized through your settings in the app. You can revoke this consent at any time, after which no further data will be transmitted to the respective entities. In legally mandated cases, we may also be obligated to share data with authorities, courts, or other public entities, for example within the framework of investigation proceedings or for the enforcement of legal claims. Such disclosures occur exclusively on the basis of corresponding legal obligations and after careful examination of lawfulness.

Data Retention and Deletion

The duration of storage of your personal data depends on the respective processing purpose and legal retention obligations. Video recordings that you store locally on your device are subject to the storage periods you have configured in the app. For example, you can specify that recordings should be automatically deleted after 24 hours, seven days, or another period of your choosing. Recordings that you have released for the data marketplace and that are stored on our servers are only retained for as long as necessary to fulfill the agreed purposes. After completion of the respective use, for example after completion of an insurance case or an official request, the data is deleted promptly, unless legal retention periods prevent this.

Personal data that we have collected as part of your contact or registration is deleted as soon as the purpose of storage no longer applies and no legal retention obligations exist. In certain cases, tax law or commercial law retention periods of up to ten years may apply, for example for invoice data or contractual documents. In these cases, the data is reliably deleted after expiration of the periods. You also have the right at any time to request the deletion of your data, provided that no overriding legal reasons prevent deletion. We comply with such deletion requests immediately and inform you about the deletion that has taken place.

Technical and Organizational Security Measures

Protecting your data from unauthorized access, loss, manipulation, or destruction is our highest priority. We therefore employ extensive technical and organizational measures to ensure a high level of protection. All data transmissions between your device and our servers occur via modern encryption technologies according to the SSL/TLS standard. This ensures that third parties cannot gain access to your data during transmission. Our servers are operated in highly secure data centers that have physical access restrictions, video surveillance, and other security precautions. The stored data itself is also encrypted, so that even in the event of unauthorized access to the servers, no readable information can be extracted.

At the organizational level, we have implemented strict access controls. Only selected employees who absolutely require these accesses for their work have access to personal data. These employees are bound to data confidentiality and receive regular data protection training. We continuously conduct security audits and update our security measures according to the state of the art. Despite all precautionary measures, we cannot guarantee absolute security, as any data transmission over the internet is fundamentally associated with certain risks. We therefore recommend that you also ensure a secure password on your side and only transmit confidential information over secure connections.

Cookies and Tracking Technologies

Our apps deliberately refrain from using analytics or marketing cookies as well as extensive tracking mechanisms. We respect your privacy and do not collect data to create detailed user profiles or for advertising purposes. Only technically necessary cookies or local storage mechanisms are used that are essential for the basic functionality of the apps. This concerns, for example, session cookies that maintain your login, or local storage that preserves your settings and preferences between different app sessions. These technically necessary cookies do not impair your privacy and serve exclusively to provide you with an optimal user experience. No sharing of this data with third parties occurs.

Your Rights as a Data Subject

As a data subject, you have extensive rights guaranteed to you by the General Data Protection Regulation. You have the right of access according to Article 15 GDPR, meaning you can request confirmation from us at any time about whether and which personal data we process about you. Furthermore, you can obtain information about the processing purposes, the categories of data processed, the recipients of the data, the planned storage duration, and other details. The right to rectification according to Article 16 GDPR enables you to request the correction of inaccurate data or the completion of incomplete data. Should you determine that stored information is no longer correct, we will update it immediately.

According to Article 17 GDPR, you have the right to erasure, provided that no legal retention obligations or other legitimate reasons prevent deletion. In certain cases, you also have the right to restriction of processing according to Article 18 GDPR, whereby we may only store your data but not further process it. The right to data portability according to Article 20 GDPR allows you to receive the personal data concerning you in a structured, commonly used, and machine-readable format and to transmit this data to another controller. Additionally, you have the right to object according to Article 21 GDPR, particularly if processing is based on a legitimate interest.

Should you have given consent to the processing of your data, you can revoke this at any time with effect for the future. The revocation does not affect the lawfulness of processing that occurred until then. To exercise any of these rights, you can contact us at any time via email at info@jrob.de. We will process your request immediately and inform you about the measures taken. Should you be of the opinion that the processing of your data violates data protection regulations, you also have the right to lodge a complaint with a supervisory authority. The supervisory authority responsible for us is the Bavarian State Office for Data Protection Supervision.

Revocation and Deletion of User Data

We place great importance on you as a user retaining sovereignty over your data. Should you decide to discontinue use of our apps or have your stored data deleted, you can contact us at any time. Contact preferably occurs via the email address info@jrob.de, through which you can describe your request in detail. We will immediately comply with your request for deletion or revocation and permanently remove all personal data that no longer needs to be stored for contract fulfillment or for legal reasons. This includes both video recordings stored on our servers as well as all other personal information such as contact data or usage profiles.

Please note that recordings stored locally on your device cannot be deleted by us. You can remove these yourself in the app or via your device's system settings. After deletion has occurred on our systems, you will receive confirmation from us documenting that your data has been properly removed. Should certain data not be immediately deletable due to legal retention obligations, we will inform you about this and block this data for further processing until the retention period has expired.

International Data Transfers

As a rule, processing of your data occurs within the European Union or the European Economic Area, where a uniformly high level of data protection is guaranteed by the GDPR. Should it be necessary in exceptional cases to transfer data to recipients in third countries outside the EU or EEA, this occurs exclusively in compliance with legal requirements. We ensure that either an adequacy decision by the European Commission exists for the respective country, appropriate safeguards such as EU standard contractual clauses have been agreed upon, or your explicit consent is present. In any case, we guarantee that even with international data transfers, your rights and your data protection are comprehensively protected.

Protection of Minors

Our apps are directed at adult users. Persons under 16 years of age should only use our services with the explicit consent of their legal guardians. We do not knowingly collect personal data from children without appropriate parental consent. Should we determine that we have inadvertently collected data from minors without required consent, we will delete it immediately. Parents or legal guardians can contact us at any time to obtain information about the data processing of their children or to initiate deletion.

Automated Decision-Making and Profiling

We do not employ automated decision-making within the meaning of Article 22 GDPR that produces legal effects concerning you or similarly significantly affects you. There is also no comprehensive profiling in which your personal characteristics are evaluated to make predictions about your behavior or preferences. The processing of your data serves exclusively the described purposes and occurs in a transparent and comprehensible manner.

Contact and Responsible Entity

Responsible for data processing within the meaning of the General Data Protection Regulation is jrob GmbH, with registered address at Jordanstr. 7, 85104 Wackerstein, Germany. For all inquiries regarding data protection, exercising your rights, or questions about the processing of your personal data, we are at your disposal. You can reach us via email at info@jrob.de. We endeavor to answer all inquiries as quickly as possible and within the statutory deadlines.

Changes to this Privacy Policy

We reserve the right to update this privacy policy as needed to adapt it to changed legal frameworks, new features of our apps, or changed operational processes. The current version of this privacy policy is always accessible via the app or on our website at this URL. We recommend that you regularly review the privacy policy to stay informed about any changes. In case of significant changes affecting your rights, we will inform you separately whenever possible. The date of the last update is indicated at the end of this statement.

Last updated: December 2025