GDPR and your data rights
This page explains how we meet the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the UK GDPR, and how you exercise your rights under them. It is written to be specific: a rights page that only recites the regulation tells you nothing about what a company actually holds.
Summary. Route Foundry collects no personal data at all — no account, no backend, no analytics, no telemetry. This website sets no cookies and loads no third-party assets. The only personal data we process is (a) hosting request logs, and (b) whatever you choose to put in an email to us. That is the whole of it.
1. Who the controller is
Divith Technologies, Kumta, Karnataka, India, is the
controller for the processing described here.
Contact for all data-protection matters:
contactnaikprajwal@gmail.com
Where we build or operate software for a client, that client is normally the controller for their users' data and we act as a processor under our contract with them. This page covers our own processing, not theirs.
2. What personal data we process
| Context | Data | Source |
|---|---|---|
| Visiting this website | IP address, timestamp, URL requested, HTTP status, user-agent string — the ordinary hosting request log | Your browser, automatically |
| Emailing us | Your email address, your message, and anything you attach | You, deliberately |
| Being a client or supplier | Name, business contact details, correspondence, contract and invoice records | You, in the course of the engagement |
| Using Route Foundry | None. Nothing reaches us | — |
| Using Route Foundry's online features | Still none for us. The points being routed, the text typed into place search, or points sampled along a route for its elevation profile — sent by the app directly to Apple or to Open-Meteo, carrying no account, no device identifier and nothing that ties one request to another | Your device, when you use that feature |
We process no special-category data (Article 9), no criminal-offence data (Article 10), and no children's data. We do not buy personal data, do not enrich it from brokers, and do not run advertising or profiling of any kind.
3. Why the app processes nothing
This is the part most worth being concrete about. Route Foundry has no
account system and no server component of ours. Routes, recorded tracks,
imported map packs and imported routing packs are written to the app's own
container on your device and stay there. Preferences live in
UserDefaults. Nothing is uploaded, and there is no database of
ours in which a record about you could exist.
Location data is used on the device, while you are navigating or recording and only then, and is never transmitted to us. Four features are online by nature — the Apple Maps basemap, Smart Routing, place search, and the elevation lookup that gives a planned route its climb figures and profile chart. The first three go to Apple under Apple's own privacy terms; the elevation lookup goes to Open-Meteo and carries only points sampled along the route. None of them goes to us: we receive nothing from them and add no identifier to them, and each can be switched off in the app.
The practical consequence: for the app, your access and erasure rights are satisfied by the app itself. Export gives you everything in an open format; deleting the app erases everything. There is no request to send us, because there is nothing on our side to disclose or delete. The full detail is in the Route Foundry privacy policy.
4. Lawful bases
| Processing | Article 6 basis | Why |
|---|---|---|
| Hosting request logs | Legitimate interests — Art. 6(1)(f) | Delivering the pages you requested, keeping the service available, and detecting abuse. A web server cannot operate without them, the data is minimal, and we neither profile nor market from it. |
| Answering your email | Legitimate interests — Art. 6(1)(f), or Art. 6(1)(b) where it concerns a contract | You wrote to us and expect a reply. We use the message only to answer it. |
| Client and supplier records | Contract — Art. 6(1)(b), and legal obligation — Art. 6(1)(c) | To perform the engagement, and to keep the tax and accounting records Indian law requires. |
We rely on consent for nothing, because we do nothing that needs it: no cookies beyond none, no tracking, no marketing email.
5. Processors we use
- Google LLC / Google Cloud EMEA — Firebase Hosting, which serves this website and keeps its request logs.
- Google LLC — Gmail, which carries our email.
That is the complete list for our own processing. We use no analytics provider, no CDN beyond the host itself, no marketing platform, no CRM and no advertising network.
The app's online features are not processors of ours. When you use Smart Routing or place search, your device talks to Apple's mapping services; when the elevation lookup runs, it talks to Open-Meteo. Those requests are made by the app on your device, the answer comes back to your device, and nothing about them reaches us — so we are not a controller or processor of that data, and each of those providers acts on its own account. Every one of those features can be switched off in the app, and the app remains usable with all of them off.
6. International transfers
We are established in India, and Google's infrastructure is global. Personal data in the two contexts above may therefore be processed outside the European Economic Area and the United Kingdom.
Where data reaches Google, transfers are governed by the European Commission's Standard Contractual Clauses (and the UK Addendum where the UK GDPR applies), which Google incorporates into its customer terms. Given that the data is limited to server logs and correspondence, and that we hold no user database, the risk that a transfer exposes anything of substance is correspondingly small.
Route Foundry sends nothing to us, anywhere, so no transfer question arises between you and us for the app's own data. Its online features do leave your device — to Apple for routing and place search, and to Open-Meteo for elevation — and those may be served from outside the EEA and the UK. Those requests carry coordinates or typed text and no identifier, they are made by your device rather than by any system of ours, and each is switchable off in the app's settings.
7. Retention
- Hosting logs — retained by Google under Firebase Hosting's own retention periods. We do not export, archive or analyse them.
- Email — kept while the matter is open, then as a record for up to 24 months.
- Files attached to a support request — deleted when the issue closes, and immediately if you ask.
- Client contract, invoice and tax records — for the period Indian tax and accounting law requires.
8. Your rights
If the GDPR or UK GDPR applies to you, you have the following rights. Next to each is what it means in our case, honestly stated.
| Right | What it means here |
|---|---|
| Access (Art. 15) | Ask what we hold about you and get a copy. For most people the answer is: an email thread, or nothing at all. |
| Rectification (Art. 16) | Have inaccurate data corrected. Tell us what is wrong and what it should say. |
| Erasure (Art. 17) | Have data deleted. We will delete correspondence and attachments on request, except where we must keep a record for tax or legal reasons. |
| Restriction (Art. 18) | Have processing paused while a dispute about accuracy or lawfulness is resolved. |
| Portability (Art. 20) | Receive data you gave us in a machine-readable format. For app data this is built in — export a route as GPX, TCX, KML, FIT or the native format, at any time, without asking anyone. |
| Object (Art. 21) | Object to processing based on legitimate interests. There is no direct marketing to object to, because we send none. |
| Withdraw consent (Art. 7) | Not applicable — we rely on consent for nothing. |
| Complain (Art. 77) | Take it to a supervisory authority. See below. |
9. How to exercise them
Email contactnaikprajwal@gmail.com with "Data request" in the subject line, and say which right you are exercising. There is no form to fill in and no account to create.
- We respond within 30 days. If a request is genuinely complex we may extend by up to two further months and will tell you why within the first month.
- There is no charge, unless a request is manifestly unfounded or repetitive.
- We may ask for enough information to be confident you are who you say you are — but no more than that, and we will not use it for anything else. Because we hold so little, verification is usually just replying from the address that wrote to us.
10. Automated decision-making
We carry out no automated decision-making producing legal or similarly significant effects, and no profiling, within the meaning of Article 22. Nothing about you is scored, ranked or classified by us.
11. How to complain
If you think we have handled your data badly, tell us first — most of what goes wrong is fixable directly and quickly.
You also have the right to complain to a supervisory authority. In the EU that is the data protection authority of the Member State where you live, work, or where the alleged infringement took place; a directory is published by the European Data Protection Board. In the UK it is the Information Commissioner's Office. Complaining to an authority does not require you to have contacted us first, and does not affect any other remedy.
12. Representative and Data Protection Officer
We have not appointed a Data Protection Officer. Article 37 requires one where an organisation is a public authority, carries out large-scale regular and systematic monitoring, or processes special categories at scale — none of which describes us. Data-protection questions go directly to the address above and are answered by the people who wrote the software.
We have likewise not appointed an Article 27 representative in the EU or UK. Article 27(2)(a) exempts processing that is occasional, does not involve large-scale special-category or criminal-offence data, and is unlikely to result in a risk to people's rights — which is the position while our app collects nothing and this site tracks nobody. If our processing ever grows past that, we will appoint a representative and name them on this page.
13. India's Digital Personal Data Protection Act
As an Indian company we are also subject to the Digital Personal Data Protection Act, 2023. Its core duties — collect only what is needed for a stated purpose, keep it no longer than necessary, secure it, and honour access and correction requests — are met by the same practices set out here, and the same contact address serves for a request or a grievance under that Act.
14. Changes
If our processing changes, this page changes with it and the effective date at the top is updated. Any change that introduced collection in the app would also require a change to the app's privacy policy, its App Store privacy labels and its privacy manifest — all four have to agree, and keeping them in agreement is part of how we ship.
This page describes our practices in good faith and in as much detail as we can. It is not legal advice, and it does not replace advice from a qualified practitioner in your own jurisdiction.