Privacy Policy Mobile
Privacy Policy
App name: When Scars (!) Become Art
Effective date: 2026-02-21
This Privacy Policy explains how personal data is collected, used, and protected in the mobile application “When Scars (!) Become Art” and related services. We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR).
1. Data Controller
Amaro Foro e.V.
Obentrautstraße 55
10963 Berlin
Deutschland
Email: info@amarodrom.de
Phone: +49 (0) 30 43205373
2. What data we collect
When you create an account or log in, we may collect and process:
Account data you provide
Full name
Email address
Username
Password (stored securely in an encrypted/hashed form; we do not store your password in plain text)
Login data
If you use Google Sign-In, we receive identifiers and basic profile information made available by Google (typically email address and name; profile photo may be included if provided).
Support/communication (if you contact us)
Any information you send us by email or through support channels.
We do not intentionally collect special category (sensitive) data. Please do not submit sensitive personal data through the app.
3. Purpose of processing
We use your personal data only to:
create and manage your user account
authenticate you and enable access to app features
provide password recovery (“Forgot password”) and account support
maintain security and prevent misuse of the service
respond to your inquiries and provide user support
Your data is not used for commercial purposes or advertising.
4. Legal basis (GDPR)
We process your data based on:
Performance of a contract / requested service (providing account access and app functionality)
Legitimate interests (security, fraud prevention, and service improvement necessary to operate the app)
Consent (only where specifically requested, e.g., optional communications)
5. Data sharing and third-party services
We do not sell your personal data.
To provide login functionality, we may use service providers acting on our behalf, including Google Firebase Authentication and Google Sign-In (where enabled). These providers process data necessary for authentication and account management.
We may also disclose personal data if required by law or by Erasmus+ programme authorities for monitoring, audit, or evaluation purposes.
6. International transfers
Some service providers may process data outside the European Economic Area (EEA). Where applicable, we rely on appropriate safeguards required under GDPR (such as Standard Contractual Clauses).
7. Storage and retention
We store personal data securely and only as long as necessary for the purposes described above, or as required by applicable law and Erasmus+ programme obligations. You may request deletion of your account as described below.
8. Your rights
You have the right to:
access your personal data
request correction or deletion
restrict processing or object where applicable
withdraw consent at any time where processing is based on consent
To exercise your rights, contact: info@amarodrom.de
You also have the right to lodge a complaint with your local data protection authority.
9. Children
The app is not intended for children under 13, and we do not knowingly collect personal data from children under 13.
10. Changes to this policy
We may update this Privacy Policy when needed. Any changes will be published on this page.