Privacy Policy

This privacy policy (privacy notice for the “Moving Types” app for iOS/iPadOS and Android) explains which personal data are processed when you use the app, for what purposes this is done and what rights you have. The app is offered in the App Store and on Google Play under the name “Moving Types App”. The provider shown in the App Store is “z zg – Zentrum Zeitbasierte Gestaltung” (centre for time-based design); on Google Play it is the developer account “Ralf Dringenberg”. When you visit our website, our website privacy policy applies.

Last updated: September 2026

1. Controller and contact

The controller responsible for data processing in the app within the meaning of the General Data Protection Regulation (GDPR) is:

Hochschule Mainz (University of Applied Sciences Mainz), Institut für Mediengestaltung, Department Medien-Design, Wallstrasse 11, 55122 Mainz, Germany

Phone: +49 6131 628-2336, e-mail: info@zeitbasierte-gestaltung.de, website: www.zeitbasierte-gestaltung.de

If you have any questions about data protection in the app, you can contact us at datenschutz@zeitbasierte-gestaltung.de.

You can contact the data protection officer of Hochschule Mainz at: Hochschule Mainz, Datenschutzbeauftragte (data protection officer), Lucy-Hillebrand-Straße 2, 55128 Mainz, Germany, e-mail: datenschutz@hs-mainz.de.

2. Purpose of the app and principles

The app accompanies the “Moving Types” exhibition and catalogue. When you scan a four-digit QR code from the catalogue, the app plays the corresponding film.

You do not need a user account and do not have to register to use the app. The app contains no advertising and does not use an advertising ID. It does not track your behaviour (no tracking) and contains no analytics or statistics tools of its own. However, the integrated scanning SDK transmits licence and usage data, for example the number of scans, to its provider (see section 5). We do not create usage profiles.

Data security: The app connects to the media server and to Scandit exclusively via encrypted connections (HTTPS/TLS). It does not permit unencrypted connections. On your device, it stores only the entries listed in section 6.

3. Camera access and scanning of QR codes

The app uses the camera solely to recognise QR codes. Before the first scan, the operating system asks you whether you allow access. The camera is only active while the scanner is open. The camera image is analysed in real time on your device.

The app does not store any camera images and does not transmit them to us or to third parties. From a recognised QR code, the app only takes a four-digit numeric code. It discards any other content on the device.

Without camera access, the app cannot recognise codes. This has no other disadvantages for you.

4. Retrieval of films from the media server

a) Nature and scope of processing

After a scan, the app retrieves the corresponding film via an encrypted connection (HTTPS) from our media server mt-app.zeitbasierte-gestaltung.de. The four-digit code is transmitted as part of the address (e.g. “…/movies/1234.mp4”). The films are streamed and are not permanently stored on your device. Apart from the request itself, the app does not send any data to the media server.

The media server automatically logs every request in server log files. In the process, the following data are processed and stored as technically necessary:

  • the IP address of your device in truncated form (for example, 11.22.33.44 becomes 11.22.0.0),
  • the date and time of the request,
  • the requested address (including the four-digit code), the status code of the response and the amount of data transferred,
  • information about the requesting program (so-called user agent): the app or the video player of the operating system, the operating system and its version and, where applicable, the device type and language setting.
b) Purposes and legal basis

Purposes: The data are used to deliver the films, to ensure stable and secure operation and to defend against and investigate attacks. We do not analyse them for advertising purposes, do not combine them with other data and do not draw any conclusions about you personally.

Legal basis: Art. 6(1)(e) and (3) GDPR in conjunction with Section 3 of the Landesdatenschutzgesetz Rheinland-Pfalz (LDSG; State Data Protection Act of Rhineland-Palatinate). The reliable and secure provision of the films serves the performance of our tasks under Section 2 of the Hochschulgesetz Rheinland-Pfalz (HochSchG; Higher Education Act of Rhineland-Palatinate).

c) Storage period

The log files are deleted automatically after 14 days. Data required to investigate a specific security incident are retained until the incident has been resolved.

d) Hosting, processing on our behalf and recipients

Like our website, the media server is hosted in Germany by our hosting provider:

ALL-INKL.COM – Neue Medien Münnich, owner: René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany

The recipient of the data listed in point a is ALL-INKL as our processor. A data processing agreement under Art. 28 GDPR is in place with ALL-INKL; under it, ALL-INKL may process the data only on our instructions and must protect them appropriately.

5. Scandit Data Capture SDK

a) Nature and scope of processing

For QR code recognition, we use the Scandit Data Capture SDK of Scandit AG, Hardturmstrasse 181, 8005 Zürich, Switzerland (“Scandit”). The recognition itself takes place entirely on your device. However, the SDK checks the app’s licence and collects usage statistics. According to Scandit’s Data Transmission Specification, the following data are transmitted to Scandit for this purpose:

  • an identifier that the SDK assigns to your installation (installation ID, see below),
  • an identifier of the licence key used,
  • the version number of the SDK,
  • the identifier of the app (com.moving-types.app for iOS, com.moving_types.app for Android),
  • the number of scans performed,
  • the device model (e.g. “iPhone 14”),
  • the operating system and its version,
  • the IP address through which the internet connection is established.

The Scandit add-on features “Analytics” and “Cloud Fallback” are not activated for the app’s licences. Therefore, neither the content of scanned codes nor camera images, recognition performance data or crash reports are transmitted to Scandit.

b) Installation ID

The SDK stores the installation ID in the app’s storage on your device. On iOS/iPadOS, the SDK generates it itself. On Android, the SDK usually uses the device’s Android ID for this purpose. From Android 8 onwards, the Android ID is different for each app (more precisely: for each app signing key), each user profile and each device. However, it stays the same when the app is reinstalled and only changes when the device is reset to its factory settings. According to Scandit, the data are not used for tracking and are not combined with other information about you. Nevertheless, the identifier and the IP address are personal data within the meaning of the GDPR.

c) Purposes and legal bases

Purposes: Scandit uses the data to check and ensure compliance with the licence, to fix errors, to compile statistical analyses, to monitor performance and to improve the software. We ourselves only receive aggregated reports in Scandit’s customer portal (e.g. the number of installations and scans).

Legal bases: The transmission of the data is based on Art. 6(1)(e) and (3) GDPR in conjunction with Section 3 LDSG. It is necessary in order to provide QR code recognition that is properly licensed, functional and stable. Storing the installation ID on your device, accessing it and, on Android, reading the Android ID are based on Section 25(2) no. 2 TDDDG (German Act on Data Protection and the Protection of Privacy in Telecommunications and Digital Services). These operations are strictly necessary so that the scanner you have requested is licensed and works.

d) Processing on our behalf and sub-processors

Scandit processes the data on the basis of the data processing agreement that forms part of Scandit’s licence terms. Scandit uses sub-processors. These include hosting providers such as Amazon Web Services Inc. and Google LLC (USA) as well as Scandit group companies, including some in the USA and the United Kingdom. The current list is available at https://www.scandit.com/privacy/subprocessors/. Under the data processing agreement, Scandit is obliged to protect the data by appropriate technical and organisational measures, to bind the persons entrusted with the processing to confidentiality and to impose equivalent data protection obligations on its sub-processors.

e) Transfers to third countries

The European Commission has found that Switzerland ensures an adequate level of data protection (adequacy decision, Decision 2000/518/EC). Where Scandit transfers data to sub-processors outside the EU or the EEA, Scandit states that it uses the standard contractual clauses of the European Commission (Art. 46(2)(c) GDPR).

f) Storage period

Under the data processing agreement, Scandit processes the data for as long as the app with the SDK is used by anyone, i.e. even after you yourself have stopped using the app. Once such use has ended altogether, Scandit deletes the personal data within a reasonable period, unless there is a statutory obligation to retain them. Scandit may retain anonymised data for product development. The installation ID remains stored on your device until you delete the app. On Android, the app usually receives the same identifier again after being reinstalled, because the identifier is derived from the Android ID or restored from the Google backup.

g) Further information

Further information can be found in Scandit’s privacy policy: https://www.scandit.com/privacy/. According to Scandit, it applies only to a limited extent to users of third-party apps. Please send any requests concerning your rights to us (see section 10).

6. Storage on your device

The app stores only the following on your device:

  • a flag indicating whether you have already completed the introduction (onboarding), so that it does not appear again every time the app is started;
  • the installation ID of the Scandit SDK (see section 5).

The app does not store a history of scanned codes or viewed films.

The legal basis is Section 25(2) no. 2 TDDDG. Insofar as personal data are processed in this context, Art. 6(1)(e) and (3) GDPR in conjunction with Section 3 LDSG applies in addition.

When you delete the app, these entries are deleted as well. On iOS/iPadOS, both entries may be included in your iCloud or device backup; on Android, only the Scandit identifier may be included (Google backup and transfer when you switch to a new device). They are restored when a backup is restored. You control these backups in your device settings.

7. Permissions and how to revoke them

The app requires the following permissions:

  • Camera: to recognise the QR codes (see section 3). You must grant this permission explicitly.
  • Internet access (on Android also: access to the network status): to retrieve the films and for the licence check.
  • On Android also technical permissions without access to personal data: vibration for feedback when scanning, and keeping the device awake during playback.

You can revoke camera access at any time:

  • iOS/iPadOS: under “Settings > Privacy & Security > Camera”
  • Android: under “Settings > Apps > Moving Types > Permissions > Camera” (the names may differ depending on the manufacturer)

The app can then no longer recognise codes. You can allow access again at any time.

8. App stores and external links

The app is offered via the App Store of Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, and via Google Play of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When you download the app, these providers process data, for example about your account and the download. They do so under their own responsibility and without any influence on our part. For more information, please refer to the privacy information of Apple (https://www.apple.com/legal/privacy/en-ww/) and Google (https://policies.google.com/privacy?hl=en).

Via App Store Connect and the Google Play Console, Apple and Google provide us with statistical information, for example on the number of installations. If you have allowed the sharing of analytics or diagnostic data with app developers in your device settings, we also receive crash reports and aggregated usage data. We use this information to understand how widely the app is used and to fix errors. The legal basis is Art. 6(1)(e) and (3) GDPR in conjunction with Section 3 LDSG. We do not use this information to identify you. Point d of section 9 explains how long we keep it.

The links in the app (e.g. to the legal notice and the privacy policy) open the respective website in your browser. The privacy policy of that website applies there; for our website, this is our website privacy policy.

9. Further information on data processing

a) Provision of data

You are under no statutory or contractual obligation to provide any data. However, without camera access the app cannot recognise codes. Without an internet connection, which gives rise to the connection data listed in sections 4 and 5, it cannot play films or check the licence.

b) Recipients

No recipients other than those named in sections 4, 5 and 8 receive any data, unless we are legally obliged to disclose them.

c) Contact by e-mail

If you write to us by e-mail, for example with a question about data protection or a request concerning your rights (see section 10), we store the data you send us, for example your e-mail address, the content of your message and, where applicable, information about the time of use or your IP address. You provide this information voluntarily. We store it in order to process your request and to contact you. We do not pass it on to third parties.

d) Storage period in other cases

Where this privacy notice does not state a specific storage period, in particular for the statistics and crash reports described in section 8 and for e-mails under point c, we store personal data only for as long as is necessary for the respective purpose or as provided for by law. Once the purpose no longer applies or a storage period prescribed by law expires, the data are routinely erased in accordance with the statutory provisions.

e) No automated decision-making

There is no automated decision-making, including profiling (Art. 22 GDPR).

10. Your rights

a) Overview of your rights

Subject to the conditions laid down in the GDPR, you have the following rights:

  • Access (Art. 15 GDPR): You can obtain confirmation as to whether we process personal data concerning you. If so, you are entitled, free of charge, to access these data and to receive a copy of them and further information about the processing, for example about the purposes, the categories of data, the recipients, the storage period and the source of the data and, in the case of transfers to third countries, about the appropriate safeguards.
  • Rectification (Art. 16 GDPR): You can request that inaccurate data be rectified without undue delay and that incomplete data be completed.
  • Erasure (Art. 17 GDPR): You can request that your data be erased without undue delay, for example if they are no longer necessary for the purposes for which they were collected, if you have objected and there are no overriding legitimate grounds for the processing, or if they have been processed unlawfully.
  • Restriction of processing (Art. 18 GDPR): You can request that we restrict processing, for example while we verify the accuracy of data that you contest, or as long as it has not yet been determined whether our grounds override your objection.
  • Data portability (Art. 20 GDPR): You can receive data that you have provided to us in a structured, commonly used and machine-readable format, or have them transmitted to another controller. This right applies only to automated processing based on consent or a contract, not to processing that is necessary for the performance of a task carried out in the public interest.
  • Objection (Art. 21 GDPR): You can object to processing based on Art. 6(1)(e) GDPR; see point b for details.
  • Automated individual decisions (Art. 22 GDPR): You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We do not make such decisions (see section 9).
  • Withdrawal of consent (Art. 7(3) GDPR): Where processing is based on your consent, you can withdraw it at any time. None of the legal bases stated in this privacy notice is consent. Independently of this, you can revoke camera access at any time in your device settings (see section 7).
  • Complaint (Art. 77 GDPR): You can lodge a complaint with a data protection supervisory authority; see point d for details.
b) Right to object under Art. 21 GDPR

You may object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(e) GDPR. We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. Point c explains how to object.

c) How to exercise your rights

Please send any requests concerning your rights, including erasure requests and objections, to the contacts named in section 1. The easiest way is to send an e-mail to datenschutz@zeitbasierte-gestaltung.de or to the data protection officer of Hochschule Mainz at datenschutz@hs-mainz.de. This also applies to data that Scandit processes on our behalf (section 5).

Since the app works without names or user accounts, we can usually only attribute data to a specific person if you provide us with additional information, for example about the time of use and your IP address (Art. 11(2) GDPR). Point c of section 9 explains how we process this information and your e-mail.

You can remove the entries on your device yourself at any time by deleting the app. Please note the information on backups in section 6 and on the Android ID in section 5.

d) Complaint to a supervisory authority

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The supervisory authority responsible for Hochschule Mainz is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz; https://www.datenschutz.rlp.de/).

11. Changes to this privacy notice

We update this privacy notice when the app, the services used or the legal requirements change. The version currently published on this page applies. The date at the beginning of this privacy notice shows when it was last updated.