1. Data controller
The data controller is Jacek Kurzawa, operator of ENTOMONE. Privacy and data enquiries: support@entomone.com or +48 572 426 363.
2. Data processed by ENTOMONE
- Account data: login, email address, display name, protected authentication data, roles, permissions, language and account settings.
- Observation data: taxon names, dates, places, sites, notes, specimen, breeding and Database information, and other content entered by the user.
- Photographs and attachments: files captured or selected by the user, their metadata, checksums and synchronisation information.
- Location: coordinates, measurement accuracy and GPS-session points, only after the user starts the location feature and grants the system permission.
- Device and session data: a random installation identifier, session tokens, synchronisation timestamps, IP address and limited server security or error logs.
ENTOMONE does not use data for advertising profiling, does not sell user data and contains no third-party advertising modules or marketing analytics.
3. Purposes and legal bases
Data is processed to provide accounts, authentication, storage, synchronisation and application functions; to secure the service and preserve data integrity; to operate optional services explicitly connected by the user; and to meet legal obligations and data-subject requests.
4. Data in the Android application
The app requests camera access only when taking a photograph and foreground location only during a point measurement or GPS session. It does not use background location.
Drafts, photographs waiting for upload and GPS points are stored in the app's private local area. Device tokens are stored in Android SecureStore; the app does not save the password. After confirmed synchronisation, a completed local draft and its photographs may be removed automatically after 48 hours. Signing out removes tokens and the cached Database list, but it does not remove unsent drafts.
5. Storage and recipients
Private user records are stored in a SQLite database in a protected ENTOMONE server directory outside the public web directory. The central database stores account, permission, storage-register and operational data required for the service. Data may be processed by the hosting provider acting for the controller.
If the user voluntarily connects Google Drive, selected photographs, exports or backups may be transferred to that user's private Drive. Publication to iNaturalist occurs only after an explicit user action. Google and iNaturalist privacy terms also apply to those services. Catalogue of Life Extended Release and GBIF are public taxonomic sources, not storage locations for private ENTOMONE accounts.
6. Retention and deletion
Account and user data is retained while the service is used. An account-deletion request places the account and the user's exclusive data in a controlled Trash state for 30 days. After that period, a controlled process removes the account, private SQLite database, central permissions and projections, exclusive media and recognised Google Drive copies.
Data genuinely shared with other authorised users may remain where necessary to preserve their rights and the integrity of a shared Database. Limited hosting backups expire under the technical retention cycle and do not return to normal runtime. Security logs are retained only as long as needed to protect the service and investigate an incident.
Access, correction or deletion requests may be sent to support@entomone.com. The controller may request identity verification.
7. User rights
Users may request access, correction, deletion, restriction, data portability or object to processing based on legitimate interests. Consent for an optional integration may be withdrawn by disconnecting that service. Users may also lodge a complaint with the Polish President of the Personal Data Protection Office.
8. Security and children
ENTOMONE uses HTTPS encryption, access control, private data stores, session tokens and backups. No system can eliminate all risk.
ENTOMONE is intended for entomologists, researchers, collectors and people documenting natural observations. It is not directed to children and must not be used to create a child's account without the involvement and responsibility of a legal guardian.
9. Policy changes
This policy may be updated when application functions, data recipients or legal requirements change. The current version and effective date are always published on this page.