Privacy Policy
Last updated: March 25, 2026
1. Data Controller
This website and the DMD HUB mobile application ("Service") are operated by:
DMD Navigation Lda
Zona Industrial de Recezinhos, Lote 3
4560-800 Penafiel, Portugal
Email: info@dmdnavigation.com
For the purposes of the EU General Data Protection Regulation (GDPR), DMD Navigation Lda is the data controller responsible for your personal data.
2. Personal Data We Collect
We collect and process the following categories of personal data:
2.1 Account Information
- Email address (required for registration)
- Display name
- Profile photo (avatar)
- Bio/signature
- Country
- Social media links (optional)
2.2 Content You Create
- Social feed posts, comments, and photos
- GPX route files and associated metadata (title, description, difficulty, images)
- Location submissions (coordinates, description, photos, videos)
- Event details and attendance
- Riding group messages and shared files
2.3 Location Data
- Riding group live tracking: When you are an active member of a riding group, your GPS coordinates, speed, and bearing may be shared with other group members in real time. This feature requires your active participation in a group and can be disabled by leaving the group.
- Location submissions: When you create a community location, the coordinates you provide are stored and shared publicly.
2.4 Technical Data
- IP address (for security and abuse prevention)
- Device type and operating system (iOS app)
- Push notification tokens (for delivering notifications)
- Authentication tokens (for maintaining your session)
3. Legal Basis for Processing
We process your personal data on the following legal bases under GDPR Article 6:
- Contract performance (Art. 6(1)(b)): Processing necessary to provide the Service (account management, content hosting, group features).
- Legitimate interest (Art. 6(1)(f)): Security measures, abuse prevention, service improvement, and analytics.
- Consent (Art. 6(1)(a)): Push notifications, optional location sharing, and non-essential cookies. You may withdraw consent at any time.
4. How We Use Your Data
- To provide and maintain the Service
- To display your profile and content to other users
- To enable riding group features including live member tracking
- To send push notifications about new content and group activity (when enabled)
- To process GPX route files for display and sharing
- To prevent abuse and enforce our Terms of Service
- To respond to support requests
5. Data Sharing
We do not sell your personal data. We may share data with:
- Other users: Your profile, posts, GPX files, and locations are visible to other users based on your privacy settings (Public/Private).
- Group members: Within riding groups, your location, speed, and shared content are visible to other group members.
- Service providers: Our hosting provider (OVH, France) processes data on our behalf under a Data Processing Agreement.
- Legal requirements: We may disclose data if required by law or to protect our rights.
6. Cookies
We use the following cookies:
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
dmdub_session |
Maintains your login session | Browser session | Essential |
dmdub_remember |
Keeps you logged in between visits | 30 days | Functional |
cookie_consent |
Remembers your cookie preferences | 365 days | Essential |
We do not use third-party analytics or advertising cookies.
7. Data Retention
- Account data: Retained as long as your account is active.
- Content: Retained as long as your account is active or until you delete it.
- Location tracking data: Real-time only; not stored beyond the active session.
- Server logs: Retained for up to 90 days for security purposes.
When you delete your account, your personal data is permanently removed. Some content (posts, comments) may be anonymized rather than deleted to preserve conversation context.
8. Your Rights Under GDPR
As an EU resident, you have the following rights:
- Right of access: Request a copy of your personal data.
- Right to rectification: Correct inaccurate personal data via your account settings.
- Right to erasure: Delete your account and all associated data.
- Right to data portability: Export your GPX files and location data.
- Right to restrict processing: Request limitation of processing.
- Right to object: Object to processing based on legitimate interest.
- Right to withdraw consent: Withdraw consent at any time (e.g., push notifications).
To exercise any of these rights, contact us at info@dmdnavigation.com or open a support ticket. We will respond within 30 days.
9. International Data Transfers
Your data is stored on servers located in the European Union (OVH, France). We do not transfer personal data outside the EU/EEA.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- HTTPS encryption for all data in transit
- Secure password hashing (bcrypt)
- HMAC-signed authentication tokens
- Access controls and role-based permissions
- Regular security updates
11. Children's Privacy
The Service is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you believe a child under 16 has provided us with personal data, please contact us and we will promptly delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of significant changes via email or in-app notification. The "Last updated" date at the top of this page indicates when the policy was last revised.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
DMD Navigation Lda
Email: info@dmdnavigation.com
Support: docs.dmdnavigation.com/support
You also have the right to lodge a complaint with the Portuguese Data Protection Authority (CNPD) or your local supervisory authority.