Privacy Policy Mobile

Privacy Policy

App name: When Scars (!) Become Art

Effective date: 2026-02-21

This Privacy Policy explains how personal data is collected, used, and protected in the mobile application “When Scars (!) Become Art” and related services. We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR).

1. Data Controller

Amaro Foro e.V.

Obentrautstraße 55

10963 Berlin

Deutschland

Email: info@amarodrom.de

Phone: +49 (0) 30 43205373

2. What data we collect

When you create an account or log in, we may collect and process:

Account data you provide

  • Full name

  • Email address

  • Username

  • Password (stored securely in an encrypted/hashed form; we do not store your password in plain text)

Login data

  • If you use Google Sign-In, we receive identifiers and basic profile information made available by Google (typically email address and name; profile photo may be included if provided).

Support/communication (if you contact us)

  • Any information you send us by email or through support channels.

We do not intentionally collect special category (sensitive) data. Please do not submit sensitive personal data through the app.

3. Purpose of processing

We use your personal data only to:

  • create and manage your user account

  • authenticate you and enable access to app features

  • provide password recovery (“Forgot password”) and account support

  • maintain security and prevent misuse of the service

  • respond to your inquiries and provide user support

Your data is not used for commercial purposes or advertising.

4. Legal basis (GDPR)

We process your data based on:

  • Performance of a contract / requested service (providing account access and app functionality)

  • Legitimate interests (security, fraud prevention, and service improvement necessary to operate the app)

  • Consent (only where specifically requested, e.g., optional communications)

5. Data sharing and third-party services

We do not sell your personal data.

To provide login functionality, we may use service providers acting on our behalf, including Google Firebase Authentication and Google Sign-In (where enabled). These providers process data necessary for authentication and account management.

We may also disclose personal data if required by law or by Erasmus+ programme authorities for monitoring, audit, or evaluation purposes.

6. International transfers

Some service providers may process data outside the European Economic Area (EEA). Where applicable, we rely on appropriate safeguards required under GDPR (such as Standard Contractual Clauses).

7. Storage and retention

We store personal data securely and only as long as necessary for the purposes described above, or as required by applicable law and Erasmus+ programme obligations. You may request deletion of your account as described below.

8. Your rights

You have the right to:

  • access your personal data

  • request correction or deletion

  • restrict processing or object where applicable

  • withdraw consent at any time where processing is based on consent

To exercise your rights, contact: info@amarodrom.de

You also have the right to lodge a complaint with your local data protection authority.

9. Children

The app is not intended for children under 13, and we do not knowingly collect personal data from children under 13.

10. Changes to this policy

We may update this Privacy Policy when needed. Any changes will be published on this page.