Privacy Policy

Effective date: 29 July 2026

This policy explains how Geocadra handles personal data across everything we operate: the web application at app.geocadra.com, the Geocadra apps for iOS and Android, free viewer accounts, and this website. It is written to satisfy the disclosure requirements of the data protection laws that apply to us — in particular the EU and UK GDPR and, where applicable, US state privacy laws such as the California Consumer Privacy Act — and it is incorporated by reference into our Terms of Service.

1. Who we are and what this policy covers

Geocadra is operated from Amsterdam, the Netherlands. In this policy, “Geocadra”, “we” and “us” refer to the operator of the Geocadra services, and we act as the data controller for the data described in section 2. You can reach us at any time via privacy@geocadra.com.

Geocadra is a field data collection and inspection platform. Contractors and consultants use it to capture GPS-tagged records, photos and form responses in the field, to import geospatial datasets (GeoJSON, Shapefile, DXF, CSV, KML), and to share results with their own clients through free viewer accounts. That shape of the product matters for privacy: much of the data flowing through Geocadra is collected by our customers, about their projects — and this policy is explicit about where our responsibility ends and theirs begins.

This policy covers personal data processed through the web application, the iOS and Android apps, free viewer accounts, our marketing website, and our sales and support channels. It does not cover third-party websites or services we link to.

2. Our two roles: controller and processor

Data protection laws distinguish between the party that decides why and how personal data is processed (the “controller”) and the party that processes it on the controller’s instructions (the “processor”). Geocadra acts in both roles, for different data:

Where we are the controller

We are the controller for the data we decide to collect in order to run Geocadra as a business: your account and login data, billing data, device and log data, cookies, support conversations and marketing preferences. Everything in this policy about purposes, legal bases, retention and your rights applies directly to this data.

Where we are the processor

We are the processor for customer content: the field records, GPS coordinates, photos, form responses, imported datasets and exports that our customers create or upload in their workspaces. Our customers — the organisations that own a workspace — are the controllers of that data. They decide what to collect in the field, whom to photograph, which datasets to import and whom to invite as a viewer. We process customer content only on their documented instructions, under a Data Processing Agreement (DPA) per Art. 28 GDPR that forms part of our Terms of Service for business customers.

If you believe your personal data appears in a Geocadra workspace — for example, you were photographed during a site inspection, or your address appears in an imported dataset — the organisation that collected it is responsible for handling your request, and your rights should be exercised against them. If you contact us instead, we will forward your request to the relevant customer and support them in responding, to the extent the law requires us to.

Free viewer accounts

Viewer accounts are free. A free account does not mean you pay with your data: we do not sell viewer data, show viewers advertising, or use viewer data for any purpose other than operating the service. For a viewer’s own account details (name, email, login) we are the controller; for the project data a viewer is invited to see, the inviting customer is the controller and we are the processor.

3. The personal data we collect

Account data

  • Name, email address, and a password (stored only as a salted hash) or single sign-on identifier.
  • Workspace membership, role (data collector or viewer), and the teams and clients your account is linked to.
  • Language and notification preferences.

Billing data (paid seats only)

  • Company name, billing address, VAT/tax ID, plan, seat count and invoice history.
  • Payment card details are collected and processed directly by our payment provider; we never store full card numbers on our systems.

Customer content (processed on our customers’ behalf)

  • Field records: GPS coordinates, capture timestamps, form responses, notes and measurements.
  • Photos taken in the app or uploaded, including embedded metadata (EXIF) such as capture time and geotags where the device records them.
  • Imported files — GeoJSON, Shapefile, DXF, CSV and KML — and generated exports (Excel, PDF, GeoJSON, Shapefile). These may contain personal data if the customer’s datasets do, such as parcel owner names or addresses.
  • Workspace metadata: project names, client names, and which viewer was invited to what.

Device and app data

  • Device model, operating system and version, app version, device language and time zone.
  • Crash reports and diagnostic logs when the app fails, so we can fix it.
  • Sync state — which records are stored offline on your device awaiting upload. Offline records stay on your device until they sync and can be removed by deleting them in the app or uninstalling it.

Website and log data

  • IP address, browser type, requested pages, referring page and timestamps, kept in server logs.
  • Cookies, as described in section 6.

Support and sales communications

  • The content of emails, chat messages and calls with our support and sales teams, and the contact details you use to reach us.

We do not intentionally collect special categories of personal data (such as health or biometric data) and ask customers not to collect them through Geocadra unless they have a lawful basis of their own to do so.

4. Mobile app permissions (iOS and Android)

The mobile apps request operating system permissions only for features that need them. Each permission is optional at the OS level, though declining it disables the corresponding feature:

  • Location (precise). Used to tag field records with GPS coordinates and show your position on the map while you are collecting data. Location is captured when you create or edit a record, and is attached to that record as customer content. We do not use your location for advertising, and we do not build movement profiles from it.
  • Camera. Used to take photos that you attach to field records. The app accesses the camera only when you open it from within a record.
  • Photo library. Used when you choose to attach an existing photo. We access only the photos you select.
  • Notifications. Used for service notifications such as sync results and workspace invitations. You can turn these off at any time.

You can review or revoke any permission in your device settings (iOS: Settings → Privacy & Security; Android: Settings → Apps → Geocadra → Permissions). The disclosures in the Apple App Store privacy label and Google Play data safety section are kept consistent with this policy.

5. Why we use personal data, and our legal bases

We process personal data only for the purposes below. Where the GDPR or a similar law applies, the right-hand column states the legal basis we rely on. We do not use personal data for purposes incompatible with these, and we never sell it.

PurposeData usedLegal basis (GDPR)
Creating and operating your account; providing the web and mobile apps; syncing field data; generating exports and reportsAccount data, customer content, device and app dataPerformance of a contract (Art. 6(1)(b))
Billing paid seats, invoicing, tax and accounting recordsBilling dataPerformance of a contract; compliance with legal obligations (Art. 6(1)(b), (c))
Securing the services: authentication, abuse and fraud prevention, logging, debugging, backupsAccount data, log data, device and app dataLegitimate interests (Art. 6(1)(f)) — keeping the services secure and reliable
Responding to support requests and service communications (e.g. sync failures, security notices)Account data, support communicationsPerformance of a contract; legitimate interests (Art. 6(1)(b), (f))
Product analytics and improving the services, where enabledUsage data, device and app dataConsent where required (Art. 6(1)(a)); otherwise legitimate interests (Art. 6(1)(f))
Marketing emails to existing customers about similar servicesAccount data (email, name)Legitimate interests with an opt-out in every message (Art. 6(1)(f)); consent where local law requires it
Establishing, exercising or defending legal claims; responding to lawful requests from authoritiesAny of the above, as relevantLegitimate interests; compliance with legal obligations (Art. 6(1)(c), (f))

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms and concluded they are not overridden; you can object at any time (section 11). Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.

6. Cookies and similar technologies

We keep our use of cookies deliberately narrow:

  • Strictly necessary cookies — session and authentication cookies that keep you signed in, security cookies that protect against cross-site request forgery, and a cookie that remembers preferences such as your language or theme. These are required for the service to function and do not need consent in most jurisdictions.
  • Analytics — if and where we use analytics that require consent under the ePrivacy rules or local law, we ask for it first through a consent banner, and the service works fully if you decline.

We do not use advertising cookies, cross-site tracking or social media pixels, and we honour the Global Privacy Control (GPC) signal where the law gives it effect. You can also delete or block cookies in your browser settings; blocking strictly necessary cookies will prevent sign-in.

7. When we share personal data

We share personal data only in the following situations, and we do not sell personal data or share it for cross-context behavioural advertising — not account data, not viewer data, not customer content:

  • Within your workspace. Data you create in a workspace is visible to other members and invited viewers according to the permissions your workspace owner configures. This sharing is controlled by our customer, not by us.
  • Subprocessors. Vetted service providers who host or support the service under contracts that bind them to confidentiality, security obligations and our instructions — currently including our EU-based hosting and storage providers, our payment provider, our email delivery provider and our support tooling. The current list is available on request at privacy@geocadra.com, and DPA customers are informed of subprocessor changes as set out in their DPA.
  • Professional advisers — lawyers, auditors and insurers, under confidentiality, where necessary.
  • Legal reasons. When a law, court order or binding request from a competent authority requires disclosure. We review every request, disclose the minimum necessary, and — where legally permitted and reasonably practicable — aim to notify the affected customer before disclosing customer content.
  • Business transfers. If Geocadra is involved in a merger, acquisition or sale of assets, personal data may be transferred as part of that transaction. This policy will continue to apply to it, and we will notify you before your data becomes subject to a different one.

8. International data transfers

Geocadra is hosted in the European Union, and we keep customer content on EU infrastructure by default. Where personal data is transferred to a country without an adequacy decision from the European Commission (or the equivalent under UK or Swiss law), we put safeguards in place: the European Commission’s Standard Contractual Clauses, supplemented where needed by the UK International Data Transfer Addendum and the Swiss FDPIC amendments, together with technical measures such as encryption in transit and at rest. You can request a summary of the safeguards applying to a specific transfer via privacy@geocadra.com.

9. How long we keep personal data

We keep personal data only as long as needed for the purposes above, then delete or irreversibly anonymise it:

CategoryRetention period
Account data (collectors and viewers)For the life of the account, then deleted or anonymised within 90 days of account closure
Customer content (field records, photos, imported and exported files)Controlled by the workspace owner. Deleted, or returned and then deleted, within 90 days after the workspace or subscription ends, unless the owner asks for earlier deletion
Encrypted backupsRotated automatically; deleted content leaves the backup cycle within 90 days
Invoices and payment records7 years under Dutch tax law — or longer where other applicable law requires it (e.g. 10 years under German commercial and tax law)
Server and security logsUp to 12 months, unless a specific incident requires longer
Support communications24 months after the ticket is closed

10. How we protect personal data

We apply technical and organisational measures appropriate to the risk, including: encryption of data in transit (TLS) and at rest; salted password hashing; role-based access controls inside workspaces and inside our own organisation; access to production data restricted to personnel who need it and logged; segregated environments; automatic encrypted backups; and vulnerability management. No system is perfectly secure, so if we learn of a personal data breach that risks your rights, we will notify the competent supervisory authority and — where the law requires — you or the affected customer without undue delay, and in any case within the deadlines that apply to us (72 hours to the authority under the GDPR).

11. Your rights

For the data we control, you can exercise the following rights to the extent the data protection law that applies to you grants them:

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — have your data deleted, subject to legal retention duties (for example, invoices we must keep for tax law).
  • Restriction — limit how we process your data while a dispute or verification is pending.
  • Portability — receive the data you provided in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time (in which case we stop, full stop).
  • Withdraw consent — wherever processing is based on it.
  • No discrimination — we will not degrade the service or charge you differently because you exercised a privacy right.

To exercise any of these, email privacy@geocadra.com from the address linked to your account, or from any address with enough information for us to verify you (we verify identity before releasing or deleting data, and we may decline requests that are manifestly unfounded or excessive, explaining why). We respond within the timeframe the applicable law prescribes — under the GDPR, one month, extendable for complex requests. Requests are free of charge except where the law permits a fee for repetitive or excessive requests. You may use an authorised agent where local law provides for it; we will verify the agent’s authority.

Remember the boundary in section 2: for personal data inside customer content, your request needs to go to the organisation that collected it. We will help route it if you contact us.

12. Additional regional provisions

European Economic Area

The GDPR applies to all processing where we are controller. Our lead supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). You have the right to lodge a complaint with it — via autoriteitpersoonsgegevens.nl — or with the supervisory authority of the EU country where you live or work. We would appreciate the chance to resolve your concern first, but you are not required to contact us before complaining.

United Kingdom and Switzerland

For UK users, the UK GDPR and Data Protection Act 2018 apply, and you may complain to the Information Commissioner’s Office (ico.org.uk). For Swiss users, the revised Federal Act on Data Protection (FADP) applies, and you may complain to the Federal Data Protection and Information Commissioner. The rights in section 11 apply in both cases. Where the law requires us to appoint a UK or Swiss representative, their details will be published in this section.

United States

For residents of California and other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas and Oregon): in the past 12 months we have collected the categories of personal information described in section 3 (identifiers, commercial information, internet activity, geolocation data where you enable it, and professional information), for the purposes in section 5, from you directly, from your devices, and from your workspace administrator. We do not sell personal information and do not share it for cross-context behavioural advertising, and we have not done so in the preceding 12 months; consequently there is no need for a “Do Not Sell or Share” link. We do not use or disclose sensitive personal information for purposes requiring a right to limit. You have the rights to know, access, correct, delete and port your personal information, and to non-discrimination, to the extent your state’s law grants them. If we deny a request, you may appeal by replying to our decision; where your state provides it, you may then contact your state Attorney General.

Everywhere else

If your country’s law grants you privacy rights beyond those listed here, nothing in this policy limits them; we handle such requests under the law that applies.

13. Children

Geocadra is a professional tool. It is not directed at children, and we do not knowingly collect personal data from anyone under 16 (or the higher age your country sets for consent to information services). If you believe a child has created an account, contact us and we will delete it. Customer content may incidentally capture minors (for example, in a site photo); responsibility for that lies with the customer as controller, and our DPA requires customers to have a lawful basis for what they collect.

14. Automated decision-making

We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. If that ever changes, we will update this policy first and provide the safeguards the law requires, including the right to human review.

15. Changes to this policy

When we change this policy, we will update the effective date above. For material changes — anything that expands what we collect, how we share it, or reduces your rights — we will give reasonable advance notice by email or an in-app notice before the change takes effect. Continuing to use Geocadra after that date constitutes acceptance of the updated policy, except where the law requires your explicit consent, in which case we will ask for it.

16. Contact, complaints and supervisory authorities

Privacy questions, requests and complaints: privacy@geocadra.com. General support: support@geocadra.com.

Geocadra is based in Amsterdam, the Netherlands.

If you are unsatisfied with our response, section 12 lists the supervisory authority you can turn to in your region. Nothing in this policy limits your right to do so.

Last updated: 29 July 2026 · This policy is incorporated into the Geocadra Terms of Service.