Last updated: 13 August 2026
 
This Privacy Policy applies to the Repobak mobile application for iOS and Android (the App). The App is published by:
 
Webmoodz Business Solutions B.V.
Hoofdstraat 43
2678 CE De Lier
The Netherlands
Dutch Chamber of Commerce number: 95668101
 
1. Who is Repobak intended for?
 
Repobak is a business application for authorised users who receive incident alerts and access information during a deployment, such as their status, the incident, route, distance and estimated time of arrival.
 
You cannot create an account in the App. Your account and access rights are provided and managed outside the App by Webmoodz or the organisation with which you are affiliated.
 
2. Who is responsible for your personal data?
 
The organisation that purchases Repobak from Webmoodz and makes it available to you (the Customer) is the controller of the personal data processed through Repobak. The Customer determines the purposes for which and the manner in which Repobak is used. This includes your account data, incident and alert content, deployment status and current location while you are en route.
 
Webmoodz Business Solutions B.V. processes this personal data solely on behalf of and in accordance with the Customer's documented instructions. Webmoodz is the processor for this processing. The relevant arrangements are recorded in a data processing agreement between Webmoodz and the Customer.
 
Webmoodz acts as an independent controller only for limited personal data it processes for its own purposes, such as customer relationship administration, security of its own systems, prevention of misuse and compliance with legal obligations. Webmoodz does not use the Customer's content or operational data for its own commercial purposes.
 
The Customer is responsible for the lawfulness, accuracy and content of the data that the Customer and its authorised users enter into or process through Repobak. If you have questions about this data or wish to exercise your privacy rights, you should first contact the Customer that gave you access to Repobak.
 
3. What data do we process?
 
Depending on how you use Repobak, the App may process the following data:
 
- Account and authentication data: your username, password during sign-in, access token, and the organisation or account to which you are linked. The password is sent solely to authenticate you and is not stored by the App on your device.
- Device and technical data: device name, manufacturer and model, operating system, app version, IP address, language, time zone, network data, push notification token, an internal device UUID, and the status of your notification and location permissions.
- Incident and deployment data: the content and priority of an alert, the incident address, your deployment status, information linked to the incident, route, distance and estimated time of arrival.
- Location data while en route: current geographic coordinates, accuracy and measurement time. Section 5 provides more information.
- Usage and security data: information required for session management, troubleshooting, security, and the operation and delivery of push notifications.
 
The App does not request access to your camera, microphone, photos or contacts and currently contains no advertising service.
 
4. Why do we process this data?
 
We process this data to:
 
- allow you to sign in securely and manage your session;
- link your account to the correct device and organisation;
- deliver push notifications;
- display and update incidents, deployment information and your current status;
- calculate a route, distance and estimated time of arrival while you are en route, and show your current position to dispatch;
- prevent misuse and secure the App and its supporting systems;
- investigate technical issues and provide support;
- comply with legal obligations and establish, exercise or defend legal claims.
 
The Customer determines the applicable legal basis for processing personal data through Repobak. Depending on the circumstances, this may include performance of a contract, a legitimate interest, consent or a legal obligation. Granting a device permission for location or notifications is a choice concerning the App's technical access and does not automatically constitute the GDPR legal basis for the Customer's processing.
 
5. Location data and your choice
 
You decide whether Repobak may access your location. You can allow or refuse location access, or disable it later, in your device settings. In the App settings, you can view the current location-access status and open the relevant device settings. If you disable location access, you can continue to use the App, but location-dependent features such as your current route, distance, arrival time and visibility to dispatch may not work.
 
Repobak uses and shares your location only when:
 
1. you are assigned to an active incident;
2. your deployment status is “en route”; and
3. you have enabled location access on your device.
 
Location sharing stops when your status is no longer “en route”, the incident ends or you are unassigned, you sign out, or you disable location access or your device's location services. Depending on your device, location sharing may remain active in the background while you are en route. Your device will display its usual location indicator or, on Android, an ongoing notification.
 
While you are en route, the App periodically sends your current position, accuracy and measurement time securely to the server. The server uses this information to support the current route, distance and estimated time of arrival and to show your current position to authorised dispatch or control-room staff involved in the deployment.
 
Only the most recent current position is used and displayed on the server. Each new position replaces the previous position. We do not store location history, the route travelled or a record of previous positions. When location sharing stops, your current position is no longer available for live display. The App also does not maintain a local queue or location history.
 
We do not use location data for advertising, marketing, profiling or tracking users outside an active journey to an incident.
 
6. Who do we share data with?
 
We do not sell your personal data or use it for advertising. To provide Repobak, data may be processed by:
 
- the organisation, dispatch centre or control room with which you are affiliated, for account administration and the operational handling of incidents;
- OneSignal, Inc., to register the device and deliver and manage push notifications;
- Apple Push Notification service (APNs) on Apple devices and Google Firebase Cloud Messaging (FCM) on Android devices, for the technical delivery of push notifications;
- Mapbox and the providers of the map data used, to display maps and support route calculations;
- our hosting, infrastructure and IT service providers, to provide, secure and maintain Repobak;
- competent authorities or other parties where required by law or necessary to protect our rights.
 
External map services may receive technical data, such as your IP address and information about the map area displayed, when map content is requested. Your live location for dispatch is processed through the Repobak server as described in Section 5.
 
OneSignal may process a push token, device and app data, IP address, language, time zone, network status, notification status and usage duration. Repobak links the push registration to an internal device UUID and may provide a username to OneSignal as an alias so that notifications reach the correct user.
 
7. Processing outside the European Economic Area
 
Some service providers may be established in or process data from countries outside the European Economic Area, including the United States. Where required, we use appropriate safeguards, such as a data processing agreement, an adequacy decision or European Commission-approved Standard Contractual Clauses.
 
8. How long do we retain data?
 
We do not retain personal data for longer than necessary for the purposes described above:
 
- Location data: only the current position is available while you are en route. No location or route history is stored.
- Local sign-in data: the access token and device UUID remain encrypted on your device until you sign out, your session expires or the local app data is removed.
- Account, device, incident and deployment data: for as long as your account is active and afterwards for as long as necessary for security, continuity, legal obligations or the arrangements with the affiliated organisation.
- Technical log and security data: for a limited period appropriate to the purpose for which it was recorded.
- Data held by external service providers: in accordance with our arrangements with those providers and their applicable retention policies.
 
The exact period may differ where the affiliated organisation determines the retention period or a statutory retention obligation applies.
 
9. Security
 
We take appropriate technical and organisational measures to protect personal data. The App transmits data over encrypted HTTPS connections. The access token and internal device UUID are stored in secure operating-system storage, such as the iOS Keychain or encrypted Android storage. Access to live location data is restricted to authorised users who need it for the active deployment. No security method can guarantee absolute security.
 
10. Your choices and rights
 
You can manage notifications and location access through the App and your device settings.
 
To the extent that the General Data Protection Regulation (GDPR) applies, you may request:
 
- access to your personal data;
- correction of inaccurate data;
- deletion of your data;
- restriction of processing;
- portability of data you provided;
- objection to processing based on a legitimate interest;
- withdrawal of consent, without affecting processing that was lawful before withdrawal.
 
You should first submit your request to the Customer that gave you access to Repobak. The Customer is responsible for handling requests concerning data processed through Repobak. Webmoodz assists the Customer in this process as a processor. If you do not know whom to contact, you may email info@webmoodz.nl, and we will refer your request to the appropriate Customer. We or the Customer may ask you to confirm your identity.
 
Because accounts are not created in the App, the App does not contain a self-service account deletion function. You may request deletion using the email address above or through your organisation's administrator. Data that we are legally required to retain may be excluded from deletion.
 
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
 
11. Children
 
Repobak is a business application and is not directed at children. We do not knowingly collect children's personal data through the App.
 
12. Changes
 
We may update this Privacy Policy when the App, our practices or applicable law changes. The current version will be published on our website. The date of the latest update appears at the top.