Roundel Privacy Policy
Last updated: 2026-08-11
Effective date: 2026-05-20
Version: 1.0
This Privacy Policy explains how Roundel BMW & MINI Diagnostics ("Roundel", "we", "our", "us") collects, uses, and protects information when you install or use the mobile application (the "App"). It is intended to satisfy the requirements of, among others, the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR and Data Protection Act 2018, the Türkiye Personal Data Protection Law No. 6698 ("KVKK"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the U.S. Children's Online Privacy Protection Act ("COPPA"), the Apple App Store Review Guidelines (esp. section 5.1) and the Apple Privacy Manifest framework, and the Google Play User Data Policy and Data Safety section.
Data controller
For the purposes of GDPR, KVKK, and equivalent laws, the data controller of any personal data processed via the App is:
Yener Unsal
Ritim İstanbul AVM, Cevizli Mah. Zühal Cad. A Blok No:46 İç Kapı No:50, 34846 Maltepe / İstanbul, Türkiye
Privacy contact: yenerunsal@yahoo.com
If we are required to designate an EU/UK representative under Article 27 GDPR or a KVKK representative under Article 5(2) of KVKK, we will list that representative below before EU/UK/Türkiye distribution.
1. Summary
- We do not collect your name, email address, postal address, contact list, advertising identifier, precise location, biometric data, financial account number, government ID, or browsing history.
- We do not sell or share personal information for cross-context behavioural advertising, as those terms are defined under CCPA/CPRA.
- We do not use advertising SDKs, analytics SDKs that track across apps, or attribution SDKs.
- We do not request the App Tracking Transparency permission on iOS because we do not track you across apps or websites owned by others.
- We do not carry out automated decision-making that produces legal or similarly significant effects (Article 22 GDPR).
- We do not run any crash reporting or analytics SDK in the current release.
- Your VIN and any diagnostic trouble codes you read from your vehicle stay on your device unless you explicitly export them via the share sheet.
2. Categories of data we process
a) Stored locally on your device
| Category | Example | Source | Storage |
|---|---|---|---|
| Adapter identifier | Bluetooth MAC | Adapter pairing | App sandbox |
| Vehicle profile choice | "F30 320i" | Your selection | App sandbox |
| Purchase entitlement | Premium-unlocked flag, signed token | Apple / Google receipt verification | App sandbox |
| Diagnostic trouble codes (DTCs) | "P0301 — cylinder 1 misfire" | Your vehicle's ECUs (read by you) | RAM during a scan; cleared when you close the screen |
| User preferences | Language, theme, units, opt-ins | Your settings | App sandbox |
This data resides in the operating system's app sandbox (Apple iOS Data Container / Android private app storage) and is removed when you uninstall the App. We do not transmit this data to our servers.
b) Sent off your device — only with your action or consent
| Category | When | Recipient | Why |
|---|---|---|---|
| Apple/Google IAP receipt | When you tap "Buy Premium" | Apple App Store / Google Play | Verify your purchase and unlock Premium |
| Files you export via the system share sheet | When you tap "Share" / "Save" | The destination app or service you choose | At your direction |
c) Data we do NOT process
- We do not collect your name, email, postal address, phone number, or contact list.
- We do not collect precise GPS location for analytics or advertising (Android requires the location permission as a prerequisite for BLE scanning; Roundel uses BLE only and does not read GPS coordinates).
- We do not access your camera, microphone, photos, calendar, or health data.
- We do not collect your IP address on our own servers (we have no servers that you connect to).
- We do not collect biometric identifiers, government identifiers, or precise health, financial, or sex-life data (these are "sensitive personal data" under GDPR Article 9 / CCPA "sensitive personal information"; we do not process them).
3. Purposes of processing and legal bases
| Purpose | Categories of data | GDPR / UK GDPR Art. 6 | KVKK Art. 5 / 6 | CCPA business purpose |
|---|---|---|---|---|
| Providing core App functionality | Adapter identifier, vehicle profile, DTCs | Art. 6(1)(b) — performance of contract | Art. 5(2)(c) — necessary for performance of contract | Performing services |
| Verifying your purchase | IAP receipt | Art. 6(1)(b) — contract | Art. 5(2)(c) | Performing services |
| Complying with legal obligations | As required | Art. 6(1)(c) | Art. 5(2)(a) | Legal compliance |
| Defending legal claims | Logs of relevant events | Art. 6(1)(f) — legitimate interest | Art. 5(2)(f) — legitimate interest | Legal compliance |
4. Data retention
| Data | Retention |
|---|---|
| Locally stored data on your device | Until you uninstall the App or clear it via system Settings → Storage |
| IAP receipt records held by Apple / Google | Per Apple / Google's own retention policies |
| Records required to defend legal claims | Up to the applicable statute of limitations |
| KVKK records of processing | At least the period required by KVKK Regulation on Erasure, Destruction or Anonymisation |
5. Recipients and third-party processors
We engage the following processors. Each is bound by a data-processing agreement (DPA) consistent with Article 28 GDPR and Article 8 KVKK.
| Processor | Purpose | Location | Safeguard for international transfer |
|---|---|---|---|
| Apple Inc. | In-App Purchase processing, App Store distribution | United States | EU Standard Contractual Clauses (Module 1), Apple App Store EULA, Apple Privacy Policy |
| Google LLC | In-App Purchase processing, Google Play distribution | United States | EU Standard Contractual Clauses, Google Play Developer DPA |
We do not sell or share personal information with data brokers, advertisers, or any other third party for advertising or profiling purposes.
6. International transfers
We do not transfer personal data outside your jurisdiction in the current release; Apple/Google IAP receipt verification is handled directly by the store provider under those companies' own transfer mechanisms.
7. Your rights
You have the rights described below. We will respond within the time limits required by applicable law (generally 30 days under GDPR/UK GDPR, 30 days under KVKK, 45 days under CCPA/CPRA, with one extension where permitted).
a) Rights under GDPR / UK GDPR (Articles 15–22)
- Access to the personal data we process about you and a copy of it
- Rectification of inaccurate personal data
- Erasure ("right to be forgotten")
- Restriction of processing
- Portability of personal data you provided to us, in a structured, commonly used, machine-readable format
- Object to processing based on legitimate interest
- Withdraw consent at any time; withdrawal does not affect the lawfulness of processing before withdrawal
- Lodge a complaint with your national supervisory authority. A list is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
To exercise any of these rights, contact yenerunsal@yahoo.com.
b) Rights under KVKK (Article 11)
Veri sahibi sıfatıyla şu haklara sahipsiniz:
- Kişisel verilerinizin işlenip işlenmediğini öğrenme
- İşlenmişse buna ilişkin bilgi talep etme
- İşlenme amacını ve amacına uygun kullanılıp kullanılmadığını öğrenme
- Yurt içinde / yurt dışında aktarıldığı üçüncü kişileri bilme
- Eksik veya yanlış işlenmişse düzeltilmesini isteme
- KVKK madde 7 çerçevesinde silinmesini veya yok edilmesini isteme
- Düzeltme / silme işlemlerinin aktarıldığı üçüncü kişilere bildirilmesini isteme
- Otomatik sistemlerle analiz neticesinde aleyhinize bir sonuç doğmasına itiraz etme
- Hukuka aykırı işleme nedeniyle zarara uğramanız hâlinde tazminat talep etme
KVKK kapsamındaki başvurularınızı yenerunsal@yahoo.com üzerinden veya yukarıdaki posta adresine "Veri Sorumlusuna Başvuru Usul ve Esasları Hakkında Tebliğ" hükümlerine uygun şekilde gönderebilirsiniz.
c) Rights under CCPA / CPRA (California residents)
You have the right to:
- Know what personal information we collect, the sources, the purposes, and the recipients
- Delete personal information we collect
- Correct inaccurate personal information
- Opt out of "sale" or "sharing" of personal information — we do not sell or share, so no opt-out is required
- Limit the use of sensitive personal information — we do not use sensitive personal information beyond what is necessary to provide the App
- Non-discrimination: we will not deny service, charge a different price, or provide a different level of quality because you exercised your CCPA rights.
We will not require you to create an account to make a verifiable consumer request. You may designate an authorized agent. To submit a request, email yenerunsal@yahoo.com. We will verify your identity using a reasonable method and respond within 45 days (extendable by another 45 days where necessary).
d) Rights under other U.S. state privacy laws
Equivalent rights apply under the Virginia Consumer Data Protection Act, Colorado Privacy Act, Connecticut Data Privacy Act, Utah Consumer Privacy Act, Texas Data Privacy and Security Act, Oregon Consumer Privacy Act, Montana Consumer Data Privacy Act, and similar state laws. Contact yenerunsal@yahoo.com.
e) Rights under Brazil's LGPD, Australia's Privacy Act, Canada's PIPEDA
Equivalent access, correction, deletion, and complaint rights apply. Contact yenerunsal@yahoo.com.
8. Children's privacy
- The App is not directed to children under 13 (U.S. COPPA) and we do not knowingly collect personal information from such children.
- In the European Economic Area, the App is not directed to children under 16 absent verifiable parental consent (Article 8 GDPR), or such lower age (not below 13) as the law of an EEA Member State permits.
- The App is rated 4+ on the Apple App Store and Everyone / appropriate equivalent on Google Play, but contains technical content intended for adult drivers and technicians.
- If you believe a child has provided personal information to us, please contact yenerunsal@yahoo.com and we will delete it promptly.
9. Mobile-app permissions
The App requests the following platform permissions. Each is requested with a clear in-app rationale at the moment it is needed (just-in-time), in line with Apple's privacy guidance and Google Play's User Data policy.
| Permission | Why we need it | When requested | Optional? |
|---|---|---|---|
Bluetooth (iOS NSBluetoothAlwaysUsageDescription; Android BLUETOOTH_SCAN, BLUETOOTH_CONNECT) |
Discover and connect to your Bluetooth Low Energy OBD-II adapter | First connection attempt | Required for BLE adapters |
| Location — coarse / approximate (Android only) | Android requires location permission as a prerequisite for BLE scanning. We do not read or store GPS coordinates. | First BLE scan | Required by Android OS, not by us |
| Internet | Verify in-app purchases | First purchase | Required for purchases |
| Notifications | Optional connection-status alerts | First connection | Optional |
| Photo Library / Files (iOS / Android) | Save exported diagnostic logs through the system share sheet or file picker | When you tap "Save" or "Share" | Optional |
We do not access your camera, microphone, contacts, calendar, health, fitness, sensors beyond Bluetooth, precise GPS, or any system identifier that could re-identify you.
10. Apple App Tracking Transparency (ATT)
We do not track you across apps or websites owned by other companies, and we do not present an ATT permission prompt. The App's tracking declaration in App Store Connect is "Data Not Collected" / "Data Not Linked to You" / "Data Not Used to Track You".
11. Apple Privacy Manifest and Google Play Data Safety
- The App ships with a Privacy Manifest (
PrivacyInfo.xcprivacy) declaring the minimal set of data types collected and the required-reason API uses (UserDefaults,FileTimestamp,SystemBootTime,DiskSpacewhere applicable). - Our Google Play Data Safety form matches this Privacy Policy. If there is any discrepancy, this Privacy Policy controls and we will update the Data Safety form as soon as possible.
12. Security
We apply the security measures appropriate to the sensitivity of the limited data we process:
- Platform-provided cryptographic stores for sensitive material (Apple Keychain on iOS, Android Keystore on Android)
- TLS 1.2+ for any data transmitted off the device (purchase verification)
- App-sandbox isolation enforced by the operating system
- We do not store passwords, payment credentials, or device-unique advertising identifiers
No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
13. Personal data breach notification
If we become aware of a personal-data breach affecting you, we will notify the competent supervisory authority within 72 hours in accordance with Article 33 GDPR (and equivalent KVKK / U.S. state breach-notification timelines), and we will notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms (Article 34 GDPR).
14. Cookies and similar technologies
The App does not use cookies. It does not embed analytics web views or third-party trackers. If we publish a website (e.g. roundel.app), that website's cookie practices are described in its own cookie notice.
15. Do Not Track
The App does not respond to browser "Do Not Track" signals because the App is not a web browser and does not perform cross-site tracking. Global Privacy Control signals received by any companion website will be honoured.
16. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will trigger an in-app notice on the next launch and a notice on this page. The "Last updated" date at the top indicates the most recent revision. Continued use of the App after a change constitutes acceptance of the new policy. Where the law requires renewed consent, we will request it.
17. Contact
| Topic | Contact |
|---|---|
| Privacy / data subject requests | yenerunsal@yahoo.com |
| KVKK başvuruları | yenerunsal@yahoo.com |
| EU representative (Article 27 GDPR) | [TBD before EU launch] |
| UK representative (UK GDPR) | [TBD before UK launch] |
| Türkiye veri sorumlusu | Yener Unsal, Ritim İstanbul AVM, Cevizli Mah. Zühal Cad. A Blok No:46 İç Kapı No:50, 34846 Maltepe / İstanbul, Türkiye |
| General | yenerunsal@yahoo.com |