Privacy Policy – M-KART App
This is a machine-assisted translation of the German-language privacy policy for the M-KART app (GDPR/DSGVO). In case of any discrepancy, the German version is authoritative.
1. Scope
This privacy policy applies to the mobile application M-KART (available for iOS and Android). The separate privacy policy of the website applies to our website. The M-KART app is a purely professional application (B2B) for employees of companies that use M-KART; it is not intended for consumers or children.
2. Controller
AUPOS IQ GmbHZur Steinkuhle 8
D-48341 Altenberge, Germany
Phone: +49 2505-9387723
Email: datenschutz@aupos-iq.de
Website: www.aupos-iq.de
Managing directors: Patrick Schulze, David Schulze, Jörg Schulze Greiving
Where M-KART is operated in the customer's own data center (on-premises), the deploying company (your employer) is the controller under data protection law for the business and employee data processed in M-KART; AUPOS IQ GmbH provides the app. For questions about the data processed about you as an employee, please contact your employer first.
3. Data processed by the app
3.1 Account data
To sign in, we process your username, password and a session token (JWT). Accounts are created by the administrator of the deploying company (no self-registration). Employee master data (name; email/phone only where stored in the system) is retrieved from your company's server.
3.2 Content data
Order, fault, ticket, time-tracking, material and asset data. This data is cached locally on the device for offline use and synchronized with your company's M-KART server.
3.3 Location data
On iOS, the app may request the device location "while using the app" to show assets on the map – only while the map function is actively used. On Android, the app currently does not collect location data.
3.4 Camera and photos
The camera is used for QR/barcode scanning and for photo documentation (e.g. damage and document photos); images can be selected from and saved to the photo library.
3.5 Microphone and audio
The microphone is used exclusively for the optional AI voice assistant. Audio is processed live and is not stored by the app (see Section 7).
3.6 No diagnostic or analytics data
The app contains no analytics, crash-reporting or telemetry SDK. App logs remain locally on the device and contain no personal data. No diagnostic data is sent to third parties.
4. Purposes and legal bases
The processing serves the purposes of authentication, the assignment and handling of orders in field and service operations, and documentation. The legal bases are:
- Art. 6(1)(b) GDPR – for the performance of the employment or user relationship and of the contractually agreed functions;
- Art. 6(1)(f) GDPR – legitimate interest in functional, secure operational software.
5. Device permissions
5.1 iOS
- Camera (QR scanning and photo documentation)
- Photo library (read and save)
- Location "while using the app" (map/assets)
- Microphone (AI voice assistant)
5.2 Android
- Camera
- Access to media (images, audio, video) and file storage
- Microphone
- Internet and network status
Permissions are used only for the functions stated. You can revoke permissions at any time in the device settings; individual functions may then no longer be available.
6. Recipients of data and data flows
Your company's server (primary): All business data is transmitted to the M-KART server operated by the deploying company itself (on-premises/self-hosting). Transmission is encrypted via HTTPS/TLS (company-owned certificate authority); an unencrypted fallback is only possible within the local network. There is no shared manufacturer cloud service.
No push, no tracking, no advertising: The app does not use push services (no FCM/APNs) and does not process any data for advertising or tracking purposes.
7. AI functions (optional)
The AI functions are optional and configurable. When they are enabled, content may be sent to a cloud AI service:
- Voice assistant: live audio to OpenAI (servers in the USA).
- Chat assistant: text and context to the configured provider, by default OpenRouter (cloud). The AI's tool calls may include content from the application in the request.
The configuration allows the AI service to be switched to your own or a local server (on-premises), so that no content is transmitted to external cloud providers. Microphone audio from the voice assistant is processed live and is not stored permanently by the app.
8. Transfers to third countries
When the cloud AI functions (Section 7) are enabled, content is transmitted to services in the USA (OpenAI or OpenRouter). Such a transfer only takes place if your company enables the cloud AI; otherwise, or in on-premises operation, no data is transferred to these services. Such transfers are subject to the requirements of Art. 44 et seq. GDPR (e.g. the EU-US Data Privacy Framework or the respective provider's Standard Contractual Clauses).
9. Data storage and security
Transmission (in transit): encrypted via TLS (HTTPS, company-owned certificate authority). Within the local network, an HTTP fallback is technically possible.
Local caching (at rest): Business and ERP content is cached locally on the device in an SQLite database for offline use. This local cache is not additionally encrypted; protection is provided by the encrypted transmission (TLS), encryption at device/operating-system level (iOS Data Protection when a device passcode is set, Android file-system encryption, Windows BitLocker – where enabled), the app sandbox and the device lock/mobile device management (MDM) of the deploying company. During normal operation, the cache is cleared when you sign out.
Sensitive credentials: The sign-in token (JWT) and the API key for the AI functions are stored encrypted in the secure device storage (iOS Keychain / Android Keystore) and are deleted when you sign out. The password itself is not stored in plain text; for offline sign-in, only an irreversible (one-way), salted hash (PBKDF2/SHA-256) of the password is kept locally.
We recommend protecting the device with a passcode lock/biometrics. Local data can be removed by signing out and uninstalling the app.
10. Retention period
Local data remains on the device until you sign out or uninstall the app. On the server side, the retention period is determined by the operating company's requirements and any statutory retention obligations.
11. Accounts and deletion
The app does not offer a direct in-app deletion function. Accounts are managed on the server side by the administrator of the deploying company or by AUPOS IQ GmbH. To have your account and the associated data deleted, please send an email to datenschutz@aupos-iq.de; details of the procedure can be found on the Delete account page.
12. Your rights
Under the GDPR, you have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The supervisory authority responsible for us is:
State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia(Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen)
Kavalleriestraße 2–4
40213 Düsseldorf, Germany
www.ldi.nrw.de
13. Age rating
The M-KART app is a professional application intended exclusively for employees of the deploying companies. It is not intended for children, and we do not knowingly collect data from children.
14. Status and amendments
Last updated: June 2026. We will amend this policy if the app's functions or the legal situation change.