Privacy Policy
the „Association Experiment“ app“
As of: July 17, 2026 · Version 1.0
1. Controller and Contact
Responsible for data processing in connection with the „Association Experiment“ app (hereinafter referred to as the „App“) within the meaning of the General Data Protection Regulation (GDPR) is:
SINFOTHEK FlexCo, Zielstraße 28, 6840 Götzis, Austria
Email: info@sinfothek.at · Phone: +43 676 428 27 69
If you have any questions about data protection, you can contact us at any time using the contact details provided above.
2. Scope of Application
This Privacy Policy applies exclusively to the „Association Experiment“ app. A separate privacy policy, published on the sinfothek.at website, applies to that site. Privacy Policy (sinfothek.at/datenschutz).
3. Roles and Responsibilities
The app is used independently by professionals (e.g., therapists, researchers) to conduct the association experiment with participants. The experiment and participant data collected during the experiment are stored exclusively on the professional’s device and are not transmitted to the provider.
For this locally processed experimental and participant data, the app user is privacy officer / person responsible under data protection law, not the provider. The provider is only responsible for data that is actually transmitted to it or to service providers it engages (in particular, technical diagnostic data via Sentry and contact requests).
4. Local Processing in the App
The following processing takes place exclusively locally on the user's device, and no data is transmitted to the provider or to third parties:
- Experiment and result data (inputs, reactions, evaluation of the runs) are saved locally.
- Audio recordings remain exclusively on the device.
- Transcription (the conversion of speech to text) takes place locally on the device; audio data does not leave the device during this process.
- The read-aloud feature uses the operating system's text-to-speech functionality and is designed for offline use.
Since this data does not reach the provider, the provider does not process any personal data in this regard.
5. Device Backup and Synchronization
If the user enables device- or operating system-based backup or synchronization features (e.g., iCloud Backup, Google Backup/Sync), the operating system may copy the locally stored data to the respective service. This processing is beyond the provider’s control and is subject to the privacy policy of the respective provider (e.g., Apple, Google).
6. Error and Crash Analysis (Sentry)
To detect, analyze, and resolve errors and crashes, as well as to ensure the stability of the app, we use the „Sentry“ service. Its use is technically necessary for the operation of the app.
Provider: Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA.
Data Processed: Error and event data, technical environment and diagnostic information (including device and operating system information, app version, release/commit ID, environment, branch), a pseudonymous identifier automatically assigned by Sentry, and so-called breadcrumbs (informative log entries and the navigation history within the app). The breadcrumbs are used exclusively for tracing and reproducing errors. Experiment or content data from the association experiment is not transmitted.
Data minimization: The IP address is not sent to Sentry (it is removed before transmission); the collection of standard personal data (SendDefaultPii) is disabled. Session replays are not used.
No further analysis: The data mentioned is used exclusively for error detection and troubleshooting; no further analysis of user behavior is conducted.
Personal reference: The identifier automatically assigned by Sentry is pseudonymous; real names are not transmitted. Since pseudonymous identifiers may be linked to specific individuals, this data is treated as personal data.
Purpose: Error detection and correction, app stability and security.
Legal basis: Art. 6(1)(f) of the GDPR (legitimate interest in a stable, error-free, and secure app).
Recipient / Transfer to a Third Country: The data is transmitted to the provider of Sentry and stored and processed on servers in the United States (Iowa). Under data protection law, the United States is considered a third country without a generally equivalent level of protection. The provider (Functional Software, Inc.) is certified under the EU-U.S. Data Privacy Framework; the transfer is based on the corresponding adequacy decision by the European Commission and, additionally, on standard contractual clauses pursuant to Article 46(2)(c) of the GDPR. In addition, the data minimization measures described above are implemented.
Retention period: 90 days.
Data Processing A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with the provider.
7. Making Contact
When you contact us (e.g., by email), we process the data you provide (e.g., email address, content of the inquiry) solely for the purpose of handling your request. The legal basis for this is Article 6(1)(b) or (f) of the GDPR. The data will be deleted as soon as it is no longer needed and there are no legal retention requirements that prevent its deletion.
8. App Stores
The app can be downloaded from the respective app store (e.g., Apple App Store, Google Play). The app store operator collects data (e.g., downloads, user account, payment information) on its own responsibility. The respective store operator is responsible for this; its privacy policy applies.
9. Storage period
Personal data is stored only for as long as is necessary for the respective purposes or as required by statutory retention periods. For information on the retention period for data processed via Sentry, see Section 6 (90 days).
10. Deletion of Your Data
All experiment and content data recorded in the app is stored exclusively locally on your device stored. No data is transferred to the provider in this regard. You can access this data at any time delete completely and permanently:
- by deleting the relevant entries directly in the app, or
- by uninstalling the app from the device; this will delete all locally stored data permanently deleted.
For the technical diagnostic data transmitted to Sentry for error and crash analysis (see section 6) applies: These are automatically deleted after 90 days at the latest. In addition, you can You can request the deletion of this data at any time; simply contact us informally to do so. info@sinfothek.at.
Since no other personal data is stored by the provider via the app, for the For data stored locally, there is no need to submit a separate deletion request to the provider.
11. Your Rights
Subject to the statutory requirements, you have the following rights regarding your personal data:
- Right of Access (Art. 15 of the GDPR)
- Right to Rectification (Art. 16 of the GDPR)
- Right to Erasure (Art. 17 of the GDPR)
- Right to Restriction of Processing (Art. 18 of the GDPR)
- Right to Data Portability (Art. 20 of the GDPR)
- Right to Object to Processing (Art. 21 of the GDPR)
To exercise these rights, simply send an informal message to info@sinfothek.at.
12. Right to File a Complaint
You have the right to file a complaint with a data protection supervisory authority. The competent authority in Austria is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, email: dsb@dsb.gv.at, Website: www.dsb.gv.at.
13. No automated decision-making
Automated decision-making, including profiling as defined in Article 22 of the GDPR, does not take place.
14. Minors
The app is intended for adults who are professionals and is not intended for minors. The provider does not knowingly collect personal data from minors for its own purposes.
15. Changes to This Privacy Policy
We will update this Privacy Policy if there are changes to our data processing practices or if required by law. The most recent version published on sinfothek.at is always the one that applies.
As of: July 17, 2026 · Version 1.0