Privacy Policy
As of 4 October 2026This policy explains what data the Zoopark Erfurt mobile app (the “app”) processes when you use it, and which rights you have. It covers the app itself and this website. We keep it short because the app is deliberately simple: no accounts, no advertising, no tracking, no analytics.
1. Responsible Party
The app was developed in collaboration with the Thuringian Zoopark Erfurt, which will operate the app going forward. The responsible party (in the sense of Art. 4 No. 7 GDPR, the “controller”) is:
Thüringer Zoopark Erfurt
Am Zoopark 1, 99087 Erfurt, Germany
Developed by Yavora Genchev, Fabian Alexander Schröter and
Elina Telegin
Primary contact: Fabian Alexander Schröter
E-mail: fabi.schroeter@icloud.com
Telefon: 0361 6554151
2. Overview: What We Do Not Do
- No accounts: the app has no registration, no login and no user profile.
- No advertising and no trackers: no ad networks, no marketing pixels, no third-party analytics are integrated.
- No server-side personal data: we do not operate a backend. Apart from the information your device automatically sends when it contacts a website (see Section 4), no personal data is stored on servers we control.
- No cross-device tracking or profiling is performed, and no decisions are made against you by automated processing with legal effects (Art. 22 GDPR).
3. Data Categories Processed by the App
3.1 Location data
If you open the map and use the position feature, the app requests your precise location (GPS). Your position is used exclusively on your device to place your marker on the park map and to show you whether you are inside the zoopark. The app does not send your coordinates anywhere, does not store a location history, and stops updating the position while the app is in the background or you stop using the feature.
Accessing the location on a mobile device is subject to § 25 TDDDG. The legal basis for the subsequent on-device processing is your consent under Art. 6 (1) (a) GDPR, which you give when you accept the system permission prompt. You can withdraw your consent at any time in your device settings (“Location” on iPhone/iPad, “Location”/“Location & Security” on Android); this does not affect the legality of processing up to that point. Without the permission, all other app features keep working – you simply cannot see your own position on the map.
3.2 Camera
The camera feature is used to scan the barcodes printed on your digital ticket. Images are processed locally on your device to decode the barcode. Nothing is uploaded, and the camera is only active while you are in the scanning screen. The legal basis is your consent under Art. 6 (1) (a) GDPR (and § 25 TDDDG) when you grant the camera permission. You can deny or revoke this permission in your device settings at any time.
3.3 Device motion and orientation
If you use the direction/compass view, the app reads the orientation data from your device's built-in sensors (accelerometer and magnetometer). This data is used only to orient the view on your device and is not stored or transmitted. The legal basis is your consent under Art. 6 (1) (a) GDPR / § 25 TDDDG, which you give when you grant the corresponding system permission.
3.4 Data stored locally on your device
To make the app work well and to avoid repeated downloads, the app stores a small amount of information locally on your device (in the app's private storage area, not in the Files app):
| Data | Purpose |
|---|---|
| Your settings (e.g. language, display preferences, onboarding progress) | Restoring your preferences when you open the app |
| The last loaded news, events, feeding times and ticket prices (title, text, date, image URL) | Showing up-to-date zoo information, also briefly without an internet connection |
This data is processed on your device solely for providing the requested features (your legitimate interest in a functioning app, Art. 6 (1) (f) GDPR). You can delete it at any time by clearing the app's data in your device settings or by uninstalling the app.
4. Loading Content from Third-Party Websites
The app displays live information that it loads from the official website of the zoopark:
When your device opens these pages, the website's server receives the information that any web server necessarily receives with an HTTP request – in particular your IP address, the time of the request and your device's user agent (device type and app). The zoopark operates this website in its own responsibility and processes that data under its own data protection declaration, which you can find on zoopark-erfurt.de.
New articles and event images are likewise loaded from the zoopark's website; loading them causes the same transmission of your IP address to their server. The legal basis for making these requests is your legitimate interest in receiving current zoo information, Art. 6 (1) (f) GDPR; the processing is limited to what is necessary to provide this feature.
5. This Website
This information site is a static website hosted on Cloudflare Pages (Cloudflare, Inc., USA). It contains no cookies, no tracking scripts and no third-party content. If you visit it, Cloudflare's servers receive your IP address and standard request information (request time, user agent, requested page). Cloudflare is a US company; the transfer of your IP address to the United States is based on our legitimate interest in operating this site (Art. 6 (1) (f) GDPR) together with Art. 49 (1) (a)/(c) GDPR, and Cloudflare's data protection declarations and standard contractual clauses apply to its processing. Details: Cloudflare privacy policy.
6. App Store, Google Play and the Operating System
You download the app from the Apple App Store or Google Play. Apple and Google process data about the download, installation and (if you choose to) the purchase in their own responsibility; their respective privacy policies apply:
The operating system itself may collect diagnostic data (e.g. crash reports, usage statistics). This happens directly between your device and Apple or Google, independently of the app. You can review and disable some of this in your device settings.
7. Children
The app is suitable for visitors of all ages, including children. The app does not process any data of children on our servers. Where a system permission (e.g. location) is required, iOS/Android may ask for parental consent for children under the age of digital consent; please refer to the permission prompts shown by your device.
8. Retention and Deletion
- On your device: locally stored data (see 3.4) remains until you clear the app's data or uninstall the app.
- On our servers: there is none – we do not operate a backend.
- On third-party servers: IP addresses and request logs are retained by zoopark-erfurt.de and Cloudflare according to their respective retention policies; see their privacy declarations for details.
9. Your Rights
You have the following rights under the GDPR:
- Right of access (Art. 15) – to know whether and what data is processed about you;
- Right to rectification (Art. 16) and erasure (Art. 17);
- Right to restriction of processing (Art. 18) and objection (Art. 21);
- Right to withdraw consent (Art. 7 (3)) – e.g. by revoking a system permission or deleting the app;
- Right to lodge a complaint with a supervisory authority (Art. 77) – for us, the competent authority is the Thüringer Landesbeauftragte für den Datenschutz und die Informationsfreiheit, or your local authority where you habitually reside.
Because almost all processing happens on your own device, most rights are effectively exercised by deleting or clearing the app's data. For everything else, contact us via fabi.schroeter@icloud.com.
10. Changes to This Policy
If we change the app in a way that affects the processing of your data, we will update this policy and, where required, inform you in the app or in the release notes. The “As of” date at the top of this page tells you when the policy was last updated.