GON Inspect

Privacy Policy

This policy applies to the GON Inspect mobile application (de.goncommerce.inspect) on iOS and Android. Our website has its own separate policy.

Last updated: 2026-09-03

1. Who is responsible for your data

GON Inspect is used by companies to run their own quality-control process. That means two roles matter:

  • Your employer is the controller for the inspection data you create in the app. They decide what is inspected and why, and they keep the reports.
  • We are the processor for that data — we run the software and store the data on their behalf, under a data processing agreement pursuant to Art. 28 GDPR. We do not use it for our own purposes.

For your account itself — your name, email and sign-in — we act as controller. Our details:

GON Commerce Supply UG (haftungsbeschränkt)
Waltersdorfer Str. 82
12526 Berlin
Germany
Email: gonadlershof@gmail.com

2. What the app collects

This is the complete list. It matches the App Privacy declaration on the App Store and the Data Safety declaration on Google Play.

Data Why we need it Legal basis
Name and email address To create your account, sign you in, and identify you as the author of an inspection. Art. 6 (1)(b) GDPR — performance of a contract
Photographs you take in the app They are the evidence in an inspection report. Stored against the checklist item you attached them to. Art. 6 (1)(b) GDPR — performance of a contract
Inspection content you enter Findings, notes, verdicts, and the codes you scan. This is the report itself. Art. 6 (1)(b) GDPR — performance of a contract
Employer and role To show you the inspections belonging to your organisation and nobody else’s. Art. 6 (1)(b) GDPR — performance of a contract
Technical diagnostic data App version, device model and OS version, sent with error reports so we can fix crashes. Art. 6 (1)(f) GDPR — our legitimate interest in a working app

None of this data is used for advertising, and none of it is sold or shared with data brokers.

3. What the app does not collect

Explicitly, GON Inspect does not collect:

  • Location data. The app never requests location permission and does not record where you are.
  • Your contacts, calendar or call history.
  • Your photo library. The app sees only pictures you deliberately attach.
  • Advertising identifiers (IDFA, GAID). The app contains no advertising SDK.
  • Behavioural or cross-app tracking. There is no analytics SDK in the app.
  • Health, financial or biometric data.
  • Microphone or audio recordings.

4. Device permissions

Permission What it is used for
Camera To photograph goods and to scan QR codes and barcodes on cartons and product tags. Both happen in the same camera session. The camera is not used at any other time.
Photo library (optional) Only if you choose to attach a picture you already took. The app reads the single picture you select and nothing else.
Notifications (optional) To tell you when a sync has finished or failed.

You can withdraw any of these permissions in your device settings at any time. Withdrawing camera access will stop the app from doing its main job.

5. Where your data is stored

Application servers and the database are located in the European Union. Photographs are stored in EU object storage, separate from the database. Both are operated under data processing agreements with our infrastructure providers.

A copy of your unsynced work is held on your own device so the app can work offline. It is removed from the device once it has been uploaded successfully.

6. Transfers outside the EU

Where a customer's own staff access the service from outside the European Economic Area — for example inspection teams working in Asia — personal data is accessed from that country. Where the country in question has not received an adequacy decision from the European Commission, such access takes place on the basis of the European Commission's Standard Contractual Clauses together with supplementary technical measures, in particular encryption in transit and access control on the server side.

7. Who else sees the data

We disclose data only to:

  • Your employer, who is the controller of the inspection data you produce and can see the reports you submit;
  • Our infrastructure providers — hosting and object storage within the EU — acting as processors on our instructions under Art. 28 GDPR;
  • Public authorities, where we are legally required to disclose.

We do not sell personal data and we do not pass it to advertisers or data brokers.

8. How long we keep it

Data Retention
Your account Until you delete it, or until your employer's contract with us ends.
Inspection reports and photographs For as long as your employer requires. They are that company's business records; we delete them on the employer's instruction or 30 days after their contract ends.
Diagnostic and error data 90 days.

9. Deleting your account

In the app: Settings → Account → Delete account. You will be asked to confirm. This removes your account and your personal data without needing to contact anyone.

By email: gonadlershof@gmail.com — we will carry out the deletion and confirm when it is done.

Inspection reports remain with your employer after you delete your account, because they are that company's business records rather than personal data of yours. Your name is retained on reports you authored where your employer needs it to keep the record meaningful and to meet its own retention obligations.

10. Your rights

Under the GDPR you may request access to your data (Art. 15), its correction (Art. 16), its erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and you may object to processing based on legitimate interests (Art. 21).

Send requests to gonadlershof@gmail.com. We respond within one month. Where a request concerns inspection data controlled by your employer, we will forward it to them and tell you that we have done so.

You also have the right to complain to a supervisory authority (Art. 77 GDPR). The authority competent for us is Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin.

11. Children

GON Inspect is a workplace tool for professional use. It is not directed at children and we do not knowingly collect data from anyone under 16.

12. Security

Data is encrypted in transit using TLS. Access to a company's data is decided on the server on every request, never by the app on the device. Access to production systems by our staff is restricted and logged.

13. Changes

If we change what the app collects, we will update this page and the store declarations at the same time, and note the new date at the top. Material changes will be announced in the app.


Questions: gonadlershof@gmail.com · Support · Imprint