This English text is provided for your convenience. The legally binding version is the German original.
Ing. Thomas Postl, sole trader (Einzelunternehmer), Neusiedlerstraße 18, 2763 Pernitz, Österreich. VAT ID: ATU83556304. E-mail: [email protected]
No data protection officer has been appointed (no obligation under Art 37 GDPR).
On registration: e-mail address, name (optional), password (stored only as a hash), the chosen federal province (Bundesland) and the name of the hunting ground. For paid bookings on the website, payment is processed by Paddle (Paddle.com Market Limited, Dublin, Ireland) acting as Merchant of Record. Paddle processes the data required for the purchase and for billing (e-mail, invoice and payment data) under its own responsibility; this may involve transfers to Paddle group companies in the United Kingdom and the USA (adequacy decision or EU-US Data Privacy Framework / Standard Contractual Clauses). Details: https://www.paddle.com/legal/privacy Legal basis: Art 6 (1)(b) GDPR (contract). For paid bookings on the website, payment is processed by the payment service provider of the website acting as Merchant of Record. It processes the data required for the purchase and for billing (e-mail, invoice and payment data) under its own responsibility; this may involve transfers to its group companies in the United Kingdom and the USA (adequacy decision or EU-US Data Privacy Framework / Standard Contractual Clauses). Its privacy policy is linked during checkout on the website. Legal basis: Art 6 (1)(b) GDPR (contract).
Sign-in with Google (optional): Anyone who registers or signs in with their Google account thereby transmits to us the e-mail address, the name and the technical Google account identifier; in that case no password is stored. Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) learns on sign-in that you use Revier3D. This processing of data takes place only if you actively choose this sign-in method; registration with e-mail address and password always remains available as an alternative. Legal basis: Art 6 (1)(b) GDPR (contract). Details: policies.google.com/privacy
Hidden persons (block list): If you hide another person's posts for yourself in the ground chat or in the photo gallery, we store that selection with your membership of that hunting ground: the account numbers of the hidden members and, for persons taking part via the hunting-ground link without an account of their own, their display names. The list belongs to your account and therefore applies on all your devices, for the chat and for the photos alike. It takes effect only for you, and the hidden person is not informed of it. For anyone who takes part via the hunting-ground link without an account of their own, their hidden persons remain exclusively on the device and never reach our server. You can remove individual entries again at any time; the whole list is deleted together with the account or when you leave the hunting ground. Legal basis: Art 6 (1)(b) GDPR (contract).
Content entered by the user: the hunting ground boundary (geodata), ground facilities, paths, the cull plan, the cull list and other hunting records, as well as optionally shared live locations within the ground team. These data are visible only within the respective hunting ground (account members and persons in possession of the ground link and ground password). Legal basis: Art 6 (1)(b) GDPR. For the live location: active sharing by the user, which can be ended at any time (Art 6 (1)(a) GDPR).
Hunting ground accounting (Pro): Bookings (amount, date, category, payment method, business partner, note) and receipt photos are stored within the respective ground and are visible there only to the hunting ground manager (Revierleitung), not to other members or guests. Text recognition on receipt photos runs entirely in the browser on your device; no image is transmitted to our server or to any third party for the purpose of recognition. The ground manager can create read-only access for their tax advisor: whoever receives this link can retrieve the journal, the receipt images and the exports of the ground; every retrieval is recorded in the ground's change log, and the access can be revoked at any time. The recipient of these data is the tax advisory firm commissioned by the customer themselves. Legal basis: Art 6 (1)(b) GDPR (contract). Accounting data is subject to the retention rules of item 7; for the customer's statutory tax retention obligations (7 years, § 132 BAO, the Austrian Federal Fiscal Code) a complete export is available which remains accessible even after the end of a Pro subscription.
Photos and videos: Photos and videos can be attached to markers, records and receipts. On upload we read the time of capture and, where stored in the file, the capture coordinates, and assign them to the respective entry. In the case of photos, the stored and delivered file itself thereafter contains no EXIF data. Photos and videos can be retrieved only within the respective ground and are not publicly delivered. Legal basis: Art 6 (1)(b) GDPR (contract).
When the website is accessed: IP address, time, the address requested, user agent. Purpose: operation, troubleshooting, defence against attacks (including the throttling of repeated password attempts). Retention period: 14 days. Legal basis: Art 6 (1)(f) GDPR (legitimate interest in secure operation).
Revier3D sets only two own cookies: the technically necessary session cookie for signing in, and a cookie named lang which remembers your chosen display language (valid for 30 days; it contains only the language code and no personal data). There are no tracking, analytics or advertising cookies. Consent is not required for the session cookie (§ 165 Abs 3 TKG 2021, the Austrian Telecommunications Act). The language cookie can be changed at any time via the language setting or deleted in the browser.
For enquiries submitted via the contact form or by e-mail, we process the data you provide in order to deal with the enquiry. Legal basis: Art 6 (1)(b) or (f) GDPR.
Transactional e-mails (for example for resetting the password) are sent via the service provider Brevo (Sendinblue SAS, Paris, France); only the e-mail address and the content of the e-mail are transmitted.
If the hunting ground manager (Revierleitung) connects wildlife cameras, we store per image: the image file, the time of receipt, the time of capture stored in the image, the camera's name and location, and the sender address of the transmitting e-mail. The images reach us by one of two routes: either via a dedicated receiving address per camera (of the form [email protected]) to which the camera itself sends, or via retrieval from the manufacturer's camera portal. Mail from a sender address that has not been registered is not accepted; it is merely recorded as a log line.
Credentials which the ground manager stores for a camera portal are stored by us in encrypted form (the key is kept separately on the server) and are used exclusively for that retrieval. It is our server that logs into the portal; your IP address is not transmitted in the process.
Persons may be recognisable on wildlife camera images. The positioning and operation of the cameras is decided by the ground manager, who is responsible for the choice of location, for signage and for the legal basis (item 6.4 of the General Terms and Conditions [AGB]). We store and show the images exclusively within the respective ground, do not pass them on to third parties and do not evaluate them for any other purpose. Legal basis in the relationship with the customer: Art 6 (1)(b) GDPR (contract).
Deleted camera images remain in the ground's recycle bin for 30 days and are then permanently removed. If the ground's storage is full, the system automatically deletes the oldest camera images permanently in order to make room for new ones (item 7). If the trial ends without a subsequent subscription, or if the subscription expires, the ground no longer accepts new camera images.
Revier3D runs on a server of netcup GmbH (data centre Vienna, server location: Austria). All connections are TLS-encrypted.
For acceleration and protection against overload, the CDN and security network of Cloudflare (Cloudflare Germany GmbH, Munich) is placed in front. Cloudflare thereby processes IP addresses, connection times and requested addresses as technical connection data, but stores these only briefly and does not use them for tracking or advertising. During registration and when creating a hunting ground, Cloudflare Turnstile is also used as bot protection (a user-friendly alternative to CAPTCHAs). Legal basis: Art 6 (1)(f) GDPR (secure and available operation). Details: cloudflare.com/privacypolicy
Receipt of wildlife camera images by e-mail runs via Mailgun (Sinch Sweden AB, Stockholm) as an inbound service: the sender address, the image and the metadata of the respective e-mail are transmitted. Legal basis: Art 6 (1)(b) GDPR (contract), only where the feature is actively used by the ground manager.
In order to detect faults and security problems during live operation (open beta), we collect anonymous technical error and security reports: if a JavaScript error occurs in your browser or a resource prohibited by our Content Security Policy is blocked, the browser automatically sends a report to our server. These reports contain exclusively technical information (error message, file, line number, user agent), but no account data, account IDs, ground contents or IP addresses in the log line. We use these data exclusively for troubleshooting and do not store them with any personal reference. Legal basis: Art 6 (1)(f) GDPR (legitimate interest in stable and secure operation).
Automatic reports only in the browser: these automatic error and security reports arise exclusively in the browser version of Revier3D. The Android app and the iOS app do not send them: The app does not send them: reporting of JavaScript errors and reporting of blocked resources are both switched off there. Technical performance reports are not transmitted automatically either.
Optional loading report in a store test ground: if store plans cannot be loaded, eligible test users can explicitly send a technical report to Revier3D support by tapping “Send loading details”. It contains the store, public product identifiers and loading counts and, where available, app and operating system versions, store country, timestamps and limited technical error codes. It contains no purchase receipts, payment details, passwords, location data, hunting-ground content or free-text errors. We temporarily associate it with the signed-in account and test ground to investigate the reported problem. The report is held only in our server's memory, is removed after no more than 20 minutes and does not enter databases, log files or backups. Sending it is optional and happens only after that button is tapped; purchases and restoration work independently. Legal basis: Article 6(1)(f) GDPR (legitimate interest in providing the technical support you have requested).
For maps, the elevation model, the cadastre and place search, the Revier3D server obtains data from external sources. These queries are carried out by the server; your IP address is NOT transmitted to the third-party sources — the providers see only the requests of our server:
What is transmitted in the process are exclusively the geographical coordinates of the respective map section — no account or personal data.
Some of the data is not queried at all: place names, small monuments, forest rescue points, the official landscape model and the official specialist maps come from data sets that we download once in full in advance and keep on our server. When your hunting ground is built, only a local extract is taken from them; the body concerned does not learn where your ground lies.
Weather: your device rounds the weather location to 0.01 degrees (about one kilometre) before each query. For Austrian grounds it asks GeoSphere Austria directly for current weather and the first forecast days; for German grounds it asks Bright Sky for Deutscher Wetterdienst data. These services receive the rounded location and your device's IP address.
The supplementary forecast, wind field and fallback during a national service outage come from Open-Meteo hosted on our own infrastructure; this is the primary source in Switzerland. Your device sends the rounded weather points in the body of a request to our server. The server checks your session and subscription and processes the points temporarily. Account and session data are not forwarded to the weather service. Location-specific responses are cached briefly in memory only; no permanent weather-location logs are kept. Model synchronisation downloads whole weather models independently of individual grounds. These requests do not reach the public Open-Meteo API.
You can turn off these queries per device in the 3D view, under “Weather & sky”, using “Do not fetch weather”. From then on that device makes no weather requests. This does not undo earlier queries.
Revier3D is also available as an app for Android and iOS.Revier3D is also available as an app for phone and tablet. The app is a native shell (Capacitor) which displays the very same website in a built-in browser window: it loads revier3d.at, and it has neither a server nor a database of its own. Everything set out in this policy on the account, ground data, logfiles, cookies, hosting and third-party sources applies in the app unchanged. This item describes only what is added on the device itself.
The app requests your location only when you yourself start a function that needs it: showing your own position on the map, sending your live location to your ground team, recording a path, and the emergency button. No location is determined without your permission in the operating system, and you can withdraw that permission at any time in the device settings. What happens to the position depends on the respective function:
In the app, sending your live location and recording a path both continue while the display is switched off, so that you can put the phone away. For this the app registers a location service with the operating system which, while it runs, shows a permanently visible notification; it ends as soon as you stop the function in the app.
What is meant here is the camera of your phone, not a wildlife camera (for those, item 2.6 applies). The app opens the camera or the photo picker only when you yourself attach a photo or a video to a marker, to an entry in the planner or to a receipt. It does so through the operating system's capture and file selection and therefore receives only the files you select there; the app does not request permission to access your entire photo library. The microphone is used exclusively for the sound of a video recording. The selected file is uploaded by the very same route as in the browser and afterwards resides within the respective ground; for storage, visibility and EXIF data, item 2.2 applies unchanged. Without that action on your part, the app accesses neither the camera nor the microphone nor your photos.
The app contains no third-party analytics, advertising or crash-reporting components: no Firebase, no Google Analytics, no Crashlytics, no ad network and no advertising identifier. The app includes the display window, handling of the Android back button, the location service described in item 5.1 and the native Apple or Google purchase interface described in item 5.6. The app includes the display window, handling of the back control of the device, the location service described in item 5.1 and the native store purchase interface described in item 5.6. There is no cross-device recognition for advertising or analytics and no profiling; subscription records are assigned to the signed-in account so purchases can be restored on another supported device. Automatic technical error reports and reports about blocked resources described in item 3 are switched off in the Android and iOS apps. Automatic technical error reports and reports about blocked resources described in item 3 are switched off in the app. The separate paragraph in item 3 applies to the explicitly requested loading report in a store test ground.
If you switch on the "make available offline" card in the planner, the app stores the data of your ground needed for this on the device: the lists retrieved (for example markers, paths, the cull plan) as well as files such as map tiles, aerial imagery, terrain data, the ground boundary and photos. This copy resides exclusively on your device locally, is not transmitted to any third party and can be cleared again from the same card; it disappears entirely when you uninstall the app or delete its data in the operating system. Independently of this, the app remembers small technical details locally, for example the view you last had open, so that it opens again where you left off.
Installation and updating of the app run via Google Play (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) and the App Store (Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland) respectively. In doing so, these providers process data on the download, the installation and updates under their own responsibility, linked to your store account with them. We have no influence over this and no access to your store account. The privacy terms of the respective provider apply: policies.google.com/privacy and apple.com/legal/privacy.
Installation and updating of the app run via the store provider whose store the app was installed from. In doing so, that provider processes data on the download, the installation and updates under its own responsibility, linked to your store account with it. We have no influence over this and no access to your store account. The privacy terms of the respective store provider apply; you will find them in its store.
For a store purchase, Apple or Google processes payment using your store account under its own responsibility.For a store purchase, the store provider processes payment using your store account under its own responsibility. We do not receive full payment-card details. To verify, restore and administer access to your hunting ground, we process the payment provider, product identifier, billing period and plan, transaction or purchase identifiers, signed transaction records or purchase tokens, and the store-confirmed payment, renewal, expiry and refund status. These details are assigned to your Revier3D account and the ground selected before purchase. For this assignment, Apple receives a random account-assignment identifier and Google receives obfuscated account and profile identifiers; this does not transmit hunting-ground content. For this assignment, the store receives a random account-assignment identifier or obfuscated account and profile identifiers; this does not transmit hunting-ground content. The legal bases are performance of the contract (Article 6(1)(b) GDPR), statutory record-keeping obligations (point (c)) and our legitimate interest in preventing duplicate assignments and misuse (point (f)).
The store may notify us of changes while the app is closed. Purchase evidence and subscription status are verified on the server so that cancellation, refunds or payment recovery apply across devices. Deleting your account does not cancel the store subscription; cancel it separately with the store. Later store events must not recreate a deleted account or ground. Limited contract and transaction records are retained where necessary for statutory record keeping or to prevent an unauthorised reassignment of a purchase, subject to the principles in item 7.
Personal data are disclosed to third parties only insofar as this is necessary for the performance of the contract (payment provider, hosting), is prescribed by law or you have consented. There is no sale of data and no advertising by third parties.
Enquiries for hunting grounds outside Austria, Germany and Switzerland: If you enquire about a hunting ground in another country, we first check which geodata are available for that region. For this we pass on the area in question only, that is country, region and approximate size: to official bodies of the country concerned (survey, cadastre, forestry, environment, national geodata portals) and, where necessary, to geodata providers, namely UP42, Vexcel Data Program, SkyWatch EarthCache, Airbus OneAtlas, Intermap NEXTMap and AW3D (NTT DATA). Your name, your e-mail address and the text of your message stay with us. Some of these providers are based outside the EU (third country). Legal basis: Art 6 (1)(b) GDPR (steps taken at your request prior to entering into a contract).
As a general rule, we retain account and hunting ground data while the account exists. You can permanently delete your account in account management at any time. This also deletes hunting grounds in which you are the only member, including their files and generated 3D data. Hunting grounds with other members remain available to the team. In those grounds, we remove your chat messages, activity content attributed to your account, and your personal photo and video attachments. Finalised accounting documents and immutable laboratory reports remain subject to the rules applicable to those records. Shared records, their supporting documentation and files uploaded to the shared “Files & photos” library also remain; their direct link to your deleted account is removed. Names and other personal information entered in those records are not automatically erased or anonymised by this step. For a further erasure request, you can contact us using the details in section 8. When a paid contract ends, the ground remains stored for another 6 months under section 5.3 of the Terms and Conditions and can be reactivated by taking out a new contract; after that period, we may delete the data.
Individually deleted entries (for example markers, photos, videos, camera images) remain in the ground's recycle bin for 30 days and are then permanently removed; the ground manager can empty the recycle bin at any time. If the ground's storage is full, the system additionally deletes the oldest wildlife camera images permanently (item 2.6). Server logfiles are retained for 14 days (item 2.3). Invoice-related data are retained in accordance with the statutory tax periods (as a rule 7 years, § 132 BAO).
Backups: To guard against data loss, we back up the database daily in encrypted form (retention: 14 days) and the ground data weekly (retention: 14 weeks). For photos, videos and camera images we additionally maintain a separate backup copy, because these files are never overwritten during operation; a copy deposited there may still exist after the file has been deleted in live operation. At your request we will remove that copy as well. All backups are held on the provider's systems in Austria and are transmitted only in encrypted form.
You have the right of access (Art 15), rectification (Art 16), erasure (Art 17), restriction (Art 18), data portability (Art 20) and objection (Art 21 GDPR), as well as the right to revoke consent given at any time. For this purpose, please contact [email protected].
You may also lodge a complaint with the Austrian supervisory authority: Österreichische Datenschutzbehörde (Austrian Data Protection Authority), Barichgasse 40-42, 1030 Wien, https://www.dsb.gv.at.
Passwords are stored only as salted hashes. Access to ground data is strictly separated by tenant and is tied to the account or the ground password. Write access without sign-in is blocked at the server. Credentials that you store for retrieval from a camera portal are stored by us in encrypted form (item 2.6). Photos, videos and camera images are delivered only after the authorisation has been checked and are excluded from shared caches (CDN).
We adapt this privacy policy whenever the processing changes: for example when a further service provider is added or removed, when new functions require additional data, or when purposes, recipients or retention periods change. The version respectively published on the website applies.
As of: 21 September 2026