PrivacyPolicy.
Last updated: 2026-08-01
Cyberdelia.eu ("we", "us" or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose and safeguard your personal data when you visit https://paratracker.cyberdelia.eu and use our services, and explains your rights under applicable data protection laws, including the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act ("CCPA"/"CPRA"). This policy has been effective since 2026-08-01.
Data controller. Cyberdelia.eu, of [ADD REGISTERED BUSINESS ADDRESS], is the data controller responsible for the personal data described in this Privacy Policy — that is, the entity that decides why and how your personal data is processed. You can reach us at Cyberdelia.eu, [ADD REGISTERED BUSINESS ADDRESS] — cyberdeliaeu@gmail.com.
Data Protection Officer. Whether Article 37 GDPR obliges a business to formally designate a Data Protection Officer depends on factors such as whether its core activities involve large-scale, regular and systematic monitoring of individuals or large-scale processing of special categories of data. Regardless of whether that threshold applies to us, we have designated a privacy contact who performs the functions of a Data Protection Officer — handling data-protection queries, complaints and requests to exercise your rights — reachable at cyberdeliaeu@gmail.com.
How we collect information
Information we collect falls into two broad categories: information you voluntarily provide to us — for example, when you create an account, place an order, or contact us — and information that is collected automatically as you use our services.
Where the GDPR applies, the source matters: Article 13 governs information we collect directly from you, and Article 14 governs information we receive about you from someone else. Both apply to our sign-up flow, depending on how you choose to sign up. If you create an account directly with us using an email address and password, you give us your first name, last name, email address and password yourself — and, where you choose to add them, a phone number or postal address — so Article 13 applies and this Privacy Policy is the notice we give you about that collection at the time you provide it. If you instead choose to sign up or log in using Google, Facebook or Apple, we do not collect that information from you directly — we receive equivalent information (your name, email address and a profile picture) about you from that provider, so Article 14 applies instead; see "Signing in with a third-party account" below for what that distinction means in practice and how we meet our obligations under it.
When you visit our website, our servers automatically log standard data sent by your browser or device, such as your IP address, browser type and version, the pages you visit, the time and date of your visit, and similar diagnostic information ("log data"). On its own, this data does not usually identify you personally, but it may be combined with other information to do so.
Information we collect
We may collect the following categories of personal data:
- Account information you give us directly when you sign up with an email address and password (your first name, last name, email address and password)
- Authentication data from third-party sign-in providers — if you choose to sign up or log in using Google, Facebook or Apple instead, that provider shares your name, email address and profile picture with us so we can create and authenticate your account; we never see or store your password for those accounts
- Contact email addresses you choose to save to your own contact list inside the app
- Precise GPS location, altitude and accuracy data recorded from your device during an active mission you take part in as a PARA or CONTROLLER operator — this is the core purpose of the service
- Mission records: the missions you create, join or are invited to, and your role and assignment status on them
- Device and connection data (IP address, browser type, operating system)
- Server log files (request timestamps, error traces) generated automatically by our infrastructure
Signing in with a third-party account. If you choose to create an account or log in using Google, Facebook or Apple rather than an email and password, that provider asks for your permission and then shares your name, email address and profile picture with us so we can set up and authenticate your account — we never see or store the password for that account. You can review or revoke our access to your Google, Facebook or Apple account at any time from that provider's own account-settings page; doing so does not delete the account or data you have with us, which you can manage as described in "Your rights" below.
Because that data reaches us from Google, Facebook or Apple rather than directly from you, Article 14 GDPR treats it as data "not obtained from the data subject" and requires us to give you the same core information as if we had collected it from you ourselves — which is the purpose of this section and this Privacy Policy as a whole. We provide that information to you at the time you complete the sign-in flow (i.e. "at the latest" the moment we first communicate with you), so you know, before your account is created, what we will receive and why.
How we use your information
We use the personal data we collect for the following purposes:
- To provide, operate and maintain the mission-tracking service, including the real-time position broadcast between PARA and CONTROLLER operators
- To let you invite, and be invited by, other operators to a mission
- To monitor system health, diagnose errors and secure our infrastructure using server log files
- To comply with legal obligations and enforce our agreements
- To detect, prevent and address fraud, abuse or technical issues
Legal basis for processing (GDPR)
Where the GDPR applies, Article 6 requires us to identify a specific lawful basis for each way we use your personal data — a generic reference to "consent, contract, legal obligation and legitimate interests" is not enough on its own. The table below sets out, activity by activity, which basis we rely on and, where that basis is our "legitimate interests", what that interest actually is and how it is balanced against your rights:
| What we do | Legal basis under Article 6 GDPR |
|---|---|
| Creating and administering your account, including via Google, Facebook or Apple sign-in | Necessity for the performance of a contract with you (Art. 6(1)(b)) — we cannot provide an account without setting one up |
| Recording and broadcasting your device's location during a mission you take part in | Necessity for the performance of our contract with you — real-time location sharing between a mission's operators is the core service you signed up for (Art. 6(1)(b)) |
| Operating, securing and troubleshooting our services using server log files and device/usage data | Our legitimate interest in keeping our infrastructure available, performant and free from abuse (Art. 6(1)(f)) |
| Complying with legal obligations to which we are subject | Necessity for compliance with a legal obligation to which we are subject (Art. 6(1)(c)) |
| Establishing, exercising or defending legal claims, or protecting the rights, safety and property of us, our users or the public | Our legitimate interest in protecting our legal position and the safety of our users (Art. 6(1)(f)) |
Where we rely on our legitimate interests, we have considered whether those interests could be achieved in a way that has less impact on your privacy, and we give you the right to object to that processing as described in "Your rights" below — including an unconditional right to object whenever we process your data for direct marketing.
Sharing your information
We do not sell your personal data for monetary consideration. We may share your information with the following types of third parties, who are required to protect your data and only use it for the purposes we specify:
| Third party | Purpose |
|---|---|
| Google Sign-In | Lets you create an account or log in with your Google account. If you choose to do so, Google shares your name, email address and profile picture with us; Google processes that exchange in accordance with its own privacy policy |
| Facebook Login | Lets you create an account or log in with your Facebook account. If you choose to do so, Meta shares your name, email address and profile picture with us; Meta processes that exchange in accordance with its own privacy policy |
| Sign in with Apple | Lets you create an account or log in with your Apple ID. If you choose to do so, Apple shares your name and an email address (your real address, or a private relay address, at your choice) with us; Apple processes that exchange in accordance with its own privacy policy |
| Our hosting provider | Running our servers and storing our database and log files on our behalf |
| Telegram | We use Telegram to relay internal system and security alerts to our own operations team — this is an internal operational tool, not a user-facing feature, and it is not used to contact you |
We may also disclose personal data where required by law or in response to valid requests by courts, tribunals or public authorities, to establish or defend legal claims, or to protect the rights, property or safety of Cyberdelia.eu, our users or the public.
Business transfers
If Cyberdelia.eu is involved in a merger, acquisition, reorganisation or sale of assets, your personal data may be transferred as part of that transaction. We will notify you (for example, by posting a notice on our website or contacting you directly) before your personal data becomes subject to a different privacy policy.
International data transfers
Your personal data may be stored and processed in Italy, or in any other country where we, or our service providers, operate. In particular:
- Some of the third parties listed above in "Sharing your information" (Google Sign-In, Facebook Login, Sign in with Apple, Our hosting provider, Telegram) are based in, or process data in, countries outside the European Economic Area — most commonly the United States. Because the European Commission has not found every such country generally "adequate" outside of certified participants, we transfer personal data to these providers either (a) under the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions), where the recipient is a certified participant, or (b) under the European Commission's Standard Contractual Clauses and, for transfers from the UK, the UK International Data Transfer Addendum, each supplemented where necessary with additional technical and organisational measures.
- Where you choose to sign in using a third-party provider such as Google, Facebook or Apple, that provider acts as an independent controller of the data it processes on its own platform, and your use of its service is additionally governed by its own privacy policy and its own international-transfer safeguards.
- Where no other adequacy decision or appropriate safeguard is available for a specific, occasional transfer, we may instead rely on one of the derogations in Article 49 GDPR — most commonly your explicit, informed consent to that particular transfer, or the necessity of the transfer to perform a contract with you (for example, to ship a physical order to an address outside the EEA).
You can ask us for more information about, or a copy of the relevant safeguards for, any of these transfers by contacting our Data Protection Officer at cyberdeliaeu@gmail.com.
Automated decision-making and profiling
We do not make decisions that produce legal effects concerning you, or similarly significantly affect you, based solely on automated processing — every decision that meaningfully affects your access to our services or your account involves a human being who can review it. Some of our processing does, however, involve building profiles or automated checks, as follows:
If we ever do introduce a decision based solely on automated processing that produces legal or similarly significant effects, the GDPR gives you the right to obtain human intervention, to express your point of view, and to contest that decision (Article 22(3)); we would tell you about it and explain how to exercise that right at the time.
Data retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, or as required by applicable law.
In particular, we generally retain the following categories of data for these periods:
| Category of data | Retention period |
|---|---|
| Account and profile data | For as long as your account remains active; deleted (along with your saved contacts) when you delete your account |
| Missions you created | Kept for the mission's other operators even after you delete your account, but no longer linked to your account |
| Mission location (GPS) track logs | Retained until that specific mission is terminated by its creator or by one of its assigned controllers, at which point they are permanently deleted |
| Server log files | Retained only as long as necessary for security monitoring and diagnostics |
Where we no longer need your personal data for these purposes, we securely delete or anonymise it, unless we are required to keep it for longer to comply with a legal, accounting or reporting obligation, or to establish, exercise or defend legal claims.
Your rights
Depending on your location, you may have some or all of the following rights regarding your personal data:
- The right to be informed about how your personal data is collected, used and shared, in a concise, transparent, intelligible and easily accessible form, using clear and plain language
- The right of access to the personal data we hold about you, and to receive a copy of it
- The right to rectification of inaccurate or incomplete personal data without undue delay
- The right to erasure of your personal data ("right to be forgotten") in certain circumstances, for example where it is no longer necessary for the purposes for which it was collected
- The right to restrict the processing of your personal data in certain circumstances, for example while the accuracy of the data is contested
- The right to object, on grounds relating to your particular situation, to processing based on our legitimate interests or carried out in the public interest, and an unconditional right to object to processing for direct-marketing purposes
- The right to data portability, allowing you to receive personal data you have provided to us in a structured, commonly used and machine-readable format and to transmit it to another controller
- Rights related to automated individual decision-making, including profiling, where such a decision would produce legal effects concerning you or similarly significantly affect you
- The right to withdraw your consent at any time, free of charge and as easily as it was given, without affecting the lawfulness of processing carried out before the withdrawal
- The right to lodge a complaint with a supervisory authority — in particular in the Member State of your habitual residence, place of work, or of the place of the alleged infringement — if you consider that our processing of your personal data infringes the GDPR
How quickly we respond. We aim to act on requests to exercise these rights without undue delay, and in any event within one month of receiving your request and confirming your identity. Where a request is particularly complex or you have made a number of requests, we may extend this period by a further two months — if so, we will explain why within the first month. Making a request is free of charge, although we may charge a reasonable fee, or decline to act, where a request is manifestly unfounded or excessive.
If you are located in the European Economic Area or the UK, you can exercise these rights by contacting our Data Protection Officer at cyberdeliaeu@gmail.com. You also have the right to lodge a complaint with your local supervisory authority or, in the EU, the data protection authority of Italy.
Cookies
We use cookies and similar technologies to operate and improve our services, including for advertising and analytics purposes described above. For details about the categories of cookies we use, how long we keep them, and how to manage your preferences, please see our Cookie Policy.
Children's privacy
Our services are not directed to individuals under the age of 16, and we do not knowingly collect personal data from children, or knowingly sell or share children's personal information. We set this age at 16 because, where the GDPR applies, Article 8 treats it as the age at which a person can consent to "information society services" in their own right (Member States may lawfully set this age anywhere between 13 and 16; we apply the higher, more protective threshold across all of our services rather than vary it by country). Below that age, we require the consent of a parent or legal guardian.
Because Google, Facebook and Apple do not share a person's age with us when you sign in through them, we are not able to verify age at the point of sign-up through those providers any more precisely than each provider's own minimum-age policy allows. If we later become aware that we hold personal data from someone under 16 without the necessary consent — including data received via third-party sign-in — we will delete that data and, where applicable, close the associated account. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at Cyberdelia.eu, [ADD REGISTERED BUSINESS ADDRESS] — cyberdeliaeu@gmail.com so we can take appropriate action.
Links to other websites
Our website may contain links to third-party sites and services that are not operated by us. We have no control over, and accept no responsibility for, the content or privacy practices of those sites. We encourage you to review the privacy policy of any third-party site before providing any personal data to it; this Privacy Policy does not apply to your activities after you leave our site.
Security
We implement appropriate technical and organisational measures designed to protect your personal data against unauthorised access, alteration, disclosure or destruction. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If something goes wrong. If we become aware of a personal data breach, we investigate it and take steps to contain and remedy it. Where the GDPR applies and the breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (Article 33). Where the breach is likely to result in a high risk to your rights and freedoms, we also notify you directly and without undue delay, in plain language, describing what happened, its likely consequences, and the measures we have taken or propose to take in response (Article 34).
Accountability and data protection by design. Articles 5(2), 24 and 25 GDPR require us not only to comply with the data protection principles described in this policy, but to be able to demonstrate that compliance, and to build data protection into our services from the outset rather than bolt it on afterwards. In practice, this means we collect only the categories of data described in "Information we collect", keep it only for the periods in our retention schedule, record your cookie consent choices in an auditable registry (see our Cookie Policy), maintain records of our processing activities as required by Article 30, and assess higher-risk processing — such as large-scale interest-based-advertising profiling, where it applies to us — through a data protection impact assessment under Article 35 before we begin it.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements or for other operational reasons. If we make material changes, we will notify you by posting the updated policy on this page and revising the "Last updated" date above, and, where required by law, by providing additional notice (such as via email or an in-app notification) and seeking your consent to any new uses of your personal data.
Contact us
If you have any questions about this Privacy Policy, how we handle your personal data, or how to exercise your rights, please contact us at Cyberdelia.eu, [ADD REGISTERED BUSINESS ADDRESS] — cyberdeliaeu@gmail.com.