Privacy Policy

Version dated 09.07.2026

Note: This Privacy Policy describes the processing of personal data when using the app2dat platform, including the web application and apps for Windows, Android and iOS. It must be read together with the Terms of Use.

1. Controller and Contact

The controller responsible for operating the app2dat platform within the meaning of Art. 4 No. 7 of Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”), is:

CADADAPT GmbH
Hermann-Hesse-Str. 1, 4614 Marchtrenk, Austria
Commercial Register: FN 198500 m, Regional Court Wels
VAT ID: ATU50137908
E-mail for data protection matters: office@cadadapt.com

If a data protection officer is appointed in the future, or if there is a legal obligation to appoint one, their contact details will be added in the platform and in this Policy.

2. Allocation of Roles Between Platform and Operators

app2dat is used by clubs, associations, organisations, communities and other groups. From a data protection perspective, two levels must be distinguished:

For questions about data processing within a specific group, club or organisation, please primarily contact the respective operator. We support operators and data subjects within the scope of our legal obligations.

3. Basic Principle: Data Sharing per Group

Your central profile master data, such as name, contact details, address or date of birth, is not fully copied for every group. Membership in a group is generally a reference to your profile with a visibility and sharing rule.

4. Data Categories, Purposes and Legal Bases

The following overview summarises the most important processing activities. Details can be found in the following sections.

Processing Data categories Purpose Legal basis
Account, login, profile Name, e-mail, password hash, profile information, language, settings, authentication data Provision and administration of the user account Art. 6(1)(b) GDPR; for voluntary information, depending on the function, Art. 6(1)(b) or (a) GDPR
Groups, memberships, roles Membership, roles, shares, status, operator fields Club, group and organisation administration Art. 6(1)(b) GDPR; where controlled by the operator: processing on behalf of the operator
Chats, stories, comments, files Messages, media, files, reactions, read status, metadata Delivery, display, moderation and security Art. 6(1)(b) GDPR; where applicable Art. 6(1)(f) GDPR; in operator areas processing on behalf
Appointments, attendance, tasks Event data, participant status, QR attendance, tasks, logs Organisation of events, attendance and tasks Art. 6(1)(b) GDPR; in operator areas processing on behalf
Payments, contributions, invoices For CADADAPT services: booking, payment, invoice and tax data; for operator payments: claims, Stripe account connections/payment links, transaction references, payment status, amount, currency, time, allocation to the claim Billing of own services; technical support for member–operator payments; automatic allocation of payment status; tax obligations CADADAPT services: Art. 6(1)(b), (c) and, where applicable, (f) GDPR; operator payments: processing on behalf of the operator, where we process status and payment data in the operator area
Verification Verification result, evidence, where applicable ID/selfie/video data at the verification service, organisation documents Prevention of misuse, trustworthiness, organisation review Art. 6(1)(a), (b) or (f) GDPR; for biometric unique identification Art. 9(2)(a) GDPR
AI and automation functions Inputs, context, scripts, document/search content, logs Assistance, search, document analysis, script suggestions, automation Art. 6(1)(b) GDPR; additionally Art. 6(1)(f) GDPR; in operator areas processing on behalf
Technical operation and security IP address, timestamps, device/browser data, log data, error data, rate limits Operation, error analysis, security, prevention of misuse Art. 6(1)(f) GDPR; where applicable Art. 6(1)(c) GDPR

5. Account, Profile, Login and Minors

5.1 Registration and Profile

During registration and profile maintenance, we process in particular name, e-mail address, password in hashed form, language setting, optional profile picture, telephone number, address, date of birth, gender, location information and other voluntary information. Mandatory information is marked as such. Without required information, an account cannot be provided.

You can generally change or remove voluntary information in the platform, unless statutory retention obligations or legitimate interests, such as prevention of misuse or legal defence, prevent this.

5.2 Login via Third-Party Providers

If you log in via Google or Apple, we receive from the respective provider the data required for login, in particular e-mail address, unique user identifier and login token. Processing by Google or Apple is governed by their own privacy information.

5.3 Minors

The platform may also be used by minors, in particular in club and group areas. Use by minors is governed by the applicable statutory provisions, in particular Art. 8 GDPR and the relevant national implementing rules.

Where processing of personal data is based on consent and the platform is offered directly to a child as an information society service, effective consent can generally only be given by the child themselves from the age of 16, unless the law of the respective EU Member State provides for a lower age threshold. Under Art. 8 GDPR, a national age threshold may not be below 13 years. In Austria, the current age threshold for this is 14 years.

If the data subject is younger than the age threshold applicable in the respective country, processing based on consent is lawful only if consent has been given or authorised by a holder of parental responsibility. We may provide for appropriate measures to verify age and to obtain and document the consent of a legal guardian.

When minors register, a contact person with parental responsibility may be specified. In this context, we process the contact data required to enable administration, consent, proof and communication. Operators may set additional age or consent requirements in their groups, provided these are lawful.

Irrespective of this, certain processing activities may also be based on other legal bases, in particular performance of a contract, legal obligations, legitimate interests or processing on behalf of the respective operator. Statutory age limits, rules on legal capacity and protective provisions of the applicable national law remain unaffected.

6. Groups, Memberships and Club-Managed Profiles

For group and organisation functions, we process membership data, roles, shares, status, invitations, group memberships, fields defined by the operator and administrative actions.

Operators may create profiles for persons who do not yet have their own account (“club-managed profiles”). In this case, the data usually originates from the respective operator. The operator is responsible for lawfully recording and informing the data subject and enabling data subject rights. We process this data as a processor until the profile is transferred, linked or deleted.

If operators wish to collect special categories of personal data, such as health data, religious affiliation, political functions, biometric data or comparable sensitive information, they themselves must ensure an appropriate legal basis under Art. 9 GDPR. The platform is not intended for the collection of sensitive data without clear necessity and legal basis.

7. Communication, Content and Public Areas

For chats, private messages, group chats, stories, comments, reactions, surveys, files and images, we process the content you enter and the metadata required for delivery, display, synchronisation, prevention of misuse and moderation.

Recipients are the intended chat participants, group members, administrators/managers or the visibility groups selected by you. Content in public areas, such as publicly promoted events, public profiles or promotion content, may also be accessible without login, where this is provided for and indicated in the platform.

Transmission is encrypted. Content is stored according to the respective intended technical protection concept; end-to-end encryption exists only where expressly stated for a specific function.

8. Appointments, Attendance, Tasks and Organisation

For appointments, events, trainings, meetings, tasks and topics, we process appointment and organisation data, participant lists, status information, attendance data, QR code scans, task status and related logs. This processing serves organisation within the platform and, depending on the context, is carried out either as our own processing for performance of the contract or as processing on behalf of the respective operator.

9. Payments, Contributions, Invoices and Promotion

9.1 Own Paid Services of CADADAPT

If you book paid services directly from CADADAPT, e.g. promotion, verification services, extended functions or individual services, we process the data required for contract conclusion, service provision, payment and billing. This includes in particular master data, contact data, booking data, service data, invoice data, VAT data, payment status, transaction references, credit balances, scope of services and technical delivery data such as impressions or clicks, where these are required for proof, billing or prevention of misuse.

The purposes of processing are the provision of the booked service, payment and contract processing, issuing invoices, fulfilment of tax and corporate retention obligations, and enforcement of rights and fraud prevention. The legal bases are Art. 6(1)(b) GDPR for performance of a contract, Art. 6(1)(c) GDPR for legal obligations and Art. 6(1)(f) GDPR for legitimate interests in proof, enforcement of rights, fraud prevention and secure platform operation.

9.2 Contributions and Payments Between Members and Operators

Operators may manage contribution claims, due dates, payment purposes, payment information, Stripe account connections, payment links, payment status, payment notes, payment references and comparable group-specific fields within their groups. These payments take place within the legal relationship between the member and the operator. The respective operator decides which payment information is collected, why it is needed, who within the group receives access and for how long it is required.

If an operator activates Stripe for its group (connection of its own Stripe account), we may technically store or process the Stripe account or connection data required for this, where necessary for displaying the payment link, allocating it to the claim and automatically determining the payment status. The member may switch to the Stripe payment page via the payment link displayed in app2dat and make the payment there. Stripe processes the payment in accordance with its own terms and privacy notices.

After completion or modification of a payment, app2dat may automatically receive or retrieve status information from Stripe, e.g. payment confirmation, payment status, amount, currency, time, transaction or order reference, Stripe identifier, allocation to the claim and information about failed, cancelled, refunded or disputed payments, insofar as Stripe provides this via the interface used. This information is displayed in the respective group and serves automatic payment allocation and contribution management.

For these operator payments, we provide the technical platform and generally process the data as processor of the respective operator. We do not issue invoices for such payments, do not verify claims, do not execute payments, do not hold funds and are not a contractual party to the payment between member and operator. Where we process certain technical connection, security or protocol data in our own interest, this is additionally carried out on the basis of Art. 6(1)(f) GDPR for security, error analysis, prevention of misuse and evidentiary purposes.

9.3 Promotions and Interest-Based Delivery

Operators may book promotions within the platform for groups, events, organisations or comparable content. Such content is labelled as promotion or advertising.

To deliver promotions, we may use certain characteristics resulting from use of the platform or from your settings. These include, in particular, categories of groups or events defined by operators, e.g. sports, karate, music or comparable areas of interest, your membership in groups of certain categories, and interests that you specify, change or remove yourself in your profile settings. If you are a member of a group or are interested in certain categories, promotions from matching or similar areas may be shown to you.

The purposes of this processing are the interest- and category-appropriate delivery of promotions within app2dat, the labelling and display of promotion content, billing to the advertising operator, aggregated performance measurement and prevention of misuse and fraud. The legal basis is, insofar as the delivery of promotions is necessary for providing the platform functions, Art. 6(1)(b) GDPR; otherwise Art. 6(1)(f) GDPR based on our legitimate interests and the interests of advertising operators in relevant, non-intrusive and measurable promotion within the platform. Where legally required or separately activated by you, we base individual forms of personalisation on your consent under Art. 6(1)(a) GDPR.

You can control, change or deactivate your interests and the personalisation of promotions yourself in the profile settings. Where processing for direct advertising or interest-based promotion is based on legitimate interests, you may object to this processing at any time. After an effective objection, personal data will no longer be used for these purposes.

For this purpose, we do not use external advertising tracking across third-party websites or apps and do not set any non-essential advertising cookies without consent. No comprehensive advertising behaviour profiles are created across third-party offerings. Promotions are not delivered on the basis of special categories of personal data within the meaning of Art. 9 GDPR, e.g. health data, religious or political beliefs, trade union membership, sexual orientation or comparable sensitive characteristics. No profile-based targeted advertising is carried out towards minors.

For billing and performance measurement of promotions, we process reach data, e.g. impressions, clicks or comparable interactions, generally in aggregated form, unless personal data evaluation is required for security, prevention of misuse, billing or proof purposes.

10. Verification of Persons and Organisations

To increase trustworthiness of the platform, persons or organisations may be voluntarily verified.

Verification data is stored only for as long as required for verification status, prevention of misuse, proof and legal obligations.

11. Push Notifications, E-mail and System Communication

If you activate push notifications, we process device-related push tokens and transmit notifications via the services of the platform or operating system providers, in particular Google Firebase Cloud Messaging, Apple Push Notification service and Windows notification services. You can deactivate notifications at any time in the app or device settings.

We send system- and contract-related e-mails, such as registration, invitations, password recovery, invoices, security notices, material changes and legal notices. You will receive advertising e-mails only if consent or a legal basis exists for this; you may unsubscribe from advertising communication at any time.

12. AI Functions, Semantic Search and Automation

The platform contains AI-supported functions that are identified as such where legally required or necessary according to their nature and function. These include, in particular, support/onboarding assistants, copilot functions in the script editor, automation agents, semantic search, document analysis and OCR.

AI and analysis service providers currently include, in particular, Google Cloud services such as Vertex AI and Document AI as well as providers of OpenAI-compatible interfaces, currently Groq and DeepSeek. Only the content required for the specific request is transmitted. Where we use API, enterprise or comparable interfaces, we configure or agree, insofar as offered by the provider, processing without use of your content for the provider’s own training purposes.

Please do not enter sensitive data in AI chats or document analysis functions if processing of such data is not required for the specific purpose. AI outputs may be incorrect or incomplete and are not used as the sole basis for legally or similarly significant decisions.

13. Local Storage, Cookies and Similar Technologies

The apps and the web application store data locally on your device, in particular login tokens, settings, session information and offline caches. In the web application, cookies, LocalStorage, IndexedDB or comparable technologies may be used for this purpose.

This storage is technically necessary to provide login, security, synchronisation, offline functions and expressly requested platform functions. We currently do not use non-essential tracking, analytics or advertising cookies. If non-essential cookies or comparable technologies are used in the future, this will take place only after prior information and, where required, with active consent.

14. Technical Operation, Server Logs and Security

When accessing the platform, we process technically necessary connection and protocol data, in particular IP address, date and time, accessed resource, device and browser information, operating system, app version, technical identifiers, error data and security-relevant events. For real-time functions, a persistent connection to the server, for example via WebSocket or SignalR, may exist.

This data is used to provide the platform, analyse errors, detect misuse and attacks, implement rate limits, check permissions and ensure system security. Server logs are generally deleted or anonymised after no more than 14 days, unless a security-relevant incident, legal defence or legal obligation requires longer storage.

15. Recipients and Service Providers

Personal data may be transmitted, where required, to the following recipients or categories of recipients:

15.1 Overview of Important Service Providers

The following overview names the most important currently intended service providers and categories of service providers. The specific list may change; material changes will be announced in an appropriate manner. Operators receive information on sub-processors within the framework of processing on behalf.

Service provider/category Purpose/function Possible third-country reference
Hosting/infrastructure service providers Server operation, storage, databases, security, backups Central data storage generally in the EU; details depend on the provider used
Google Cloud, Firebase, Vertex AI, Document AI Push notifications, AI/embedding functions, OCR/document analysis, technical services EU regions where available; in case of US or third-country reference, safeguards by adequacy decision or standard contractual clauses
Apple Apple login, push notifications, app store functions possible third-country reference, in particular USA
Microsoft Windows notification services and, where applicable, platform services possible third-country reference, in particular USA
Stripe and app store payment providers Own payments to CADADAPT; for operator payments: payment links, Stripe account connections, automatic payment status and transaction information possible third-country reference depending on provider; Stripe (Stripe Payments Europe, Ltd., Ireland) additionally processes payment data as its own payment service provider under its own terms
Didit or comparable identity verification service Person and identity verification depending on provider, region and specific verification flow
Groq, DeepSeek or other OpenAI-compatible AI providers Language model functions for actively used assistance functions possible third-country reference; use only with suitable data protection legal basis and transfer safeguards
E-mail service providers System, contract, security and invoice communication depending on the provider used

16. Transfers to Third Countries

The central data storage of the platform generally takes place in the European Union. Individual service providers may also process personal data outside the European Economic Area, in particular in the case of global cloud, push, payment, identity verification or AI services.

For third-country transfers, we rely, where required, on an adequacy decision of the European Commission, for example for appropriately certified providers under the EU-U.S. Data Privacy Framework, or on appropriate safeguards under Art. 46 GDPR, in particular EU standard contractual clauses. Where required, we examine additional protective measures such as encryption, access restriction, data minimisation, EU regions and contractual assurances. Information on the specific safeguards used is provided upon request.

17. Retention Period

We store personal data only for as long as required for the respective purposes or as long as statutory retention obligations exist. In particular, the following applies:

18. Your Rights

Under the GDPR, you have in particular the following rights:

You can exercise many rights directly in the platform, such as editing your profile, changing shares, deleting content, deleting your account or exporting data. For further matters, please contact us at office@cadadapt.com.

If your matter concerns data that an operator processes in its group or organisation, the respective operator is generally the correct contact. We provide technical support where needed and within the scope of our legal obligations.

You also have the right to lodge a complaint with a data protection supervisory authority. In Austria, this is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at. You may also contact a supervisory authority at your place of residence, workplace or the place of the alleged infringement.

19. Automated Decisions and Profiling

We do not make decisions based solely on automated processing that have legal or similarly significant effects on users. In particular, final account suspensions, verification decisions or comparable significant decisions are not made solely by automated means, but are reviewed by humans.

No profiling with legal or similarly significant effects takes place. Within app2dat, however, promotions may be delivered on an interest- and category-based basis, in particular based on group categories, group memberships and interests managed by the user themselves. Users can control this personalisation in the profile settings and, where processing is based on legitimate interests, object to it at any time.

20. Data Security

We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration and unauthorised disclosure. These include in particular:

Please also protect your account and device, in particular through secure passwords, device lock, up-to-date operating systems and careful handling of shares.

21. Obligation to Provide Data

Use of the platform is voluntary. Certain information is required for an account and individual functions. If required information is not provided, the affected functions cannot be used or can only be used to a limited extent. Voluntary information can generally be omitted or removed later.

22. Changes to this Privacy Policy

We update this Privacy Policy when the platform, processing activities, service providers used, legal requirements or our security and organisational measures change. The version available in the platform applies. We will inform you of material changes in an appropriate manner. In the event of discrepancies between language versions, the German version shall prevail.

© 2026 CADADAPT GmbH — All rights reserved.