Privacy Policy
Effective Date: 21.04.2026
This Privacy Policy explains how personal data is collected, used, stored, and protected when you use the EDC16Reader website, web application, app, API, and related services.
1. Controller
The controller responsible for data processing is:
Nico Zieten
Private individual
Email: nicozieten@gmail.com
2. Scope
This Privacy Policy applies to the EDC16Reader website, web application, app, API, and related services, including services built using .NET MAUI Blazor.
3. General Use of the Service
The EDC16Reader app can generally be used without mandatory registration. Certain additional features may in the future require registration and login.
4. Categories of Data Processed
Depending on how you use the service, the following categories of data may be processed:
- Technical server and API log data
- IP address, browser type, operating system, timestamps, and request information
- Session-related cookie data required for login functionality
- Email address and password data for future account registration and login features
- Read-out ECU data states and related technical records
- Vehicle Identification Number (VIN), where required for technical assignment of ECU data states
- Messages or requests sent to the contact email address
5. ECU Data States
EDC16Reader may process and store read-out ECU data states for technical analysis, compatibility checks, software version matching, and further development of diagnostic and technical functions.
Such data may include, for example, maps, program code, calibration values, and other raw binary or compiled machine data read from control units.
These ECU data states are technical machine data and are generally not directly understandable without specialized technical knowledge. However, where such data can be linked to an identifiable person, account, or vehicle, it may be treated as personal data under applicable law.
6. Use of the VIN
The Vehicle Identification Number (VIN) is used exclusively as a technical identifier for assigning and matching ECU data states to the corresponding vehicle-related dataset.
The VIN is not used for advertising, profiling, or commercial resale of data. Where VIN-based records can be linked to an identifiable individual, such data may be treated as personal data under applicable law.
In the future, users may be able to request access to stored ECU data states associated with their vehicle, for example where a matching process based on the read-out VIN can be established.
7. Purpose of Processing
Personal data and technical data may be processed for the following purposes:
- To provide and operate the website, app, API, and related services
- To enable future account registration, login, and authenticated features
- To maintain technical stability, security, and abuse prevention
- To analyze errors, crashes, and technical problems
- To perform technical analysis of ECU data states
- To identify calibration structures, maps, software versions, and related technical characteristics
- To improve and further develop the EDC16Reader software
- To respond to user inquiries
8. Legal Basis for Processing
Data processing is carried out only where there is a valid legal basis. Depending on the specific processing activity, this may include:
- Performance of a contract or steps taken prior to entering into a contract
- Legitimate interests in operating, securing, maintaining, and improving the service
- Compliance with legal obligations
- Your consent, where required by law
9. Registration and Login
Registration is currently not required for general use of the app. If account-based functions are introduced, the data processed for registration and login may include an email address and password.
Passwords are not stored in plain text. They are intended to be stored in hashed form using appropriate current security standards.
10. Cookies and Session Handling
This website and web application may use cookies or similar technologies that are necessary for session handling, login functionality, and authenticated access.
These cookies are used only to provide required technical functions of the service.
11. Log Data
When you access the website, app, or API, certain technical data may be collected automatically. This may include IP address, browser type, operating system, date and time of access, requested resources, and related technical request information.
This information is used for technical operation, troubleshooting, security, abuse prevention, and service improvement.
12. Hosting and Infrastructure
The service is operated using self-hosted infrastructure controlled by the controller. The systems used for the regular operation of the service are hosted on devices located under the controller's own control.
Website and API access are provided via HTTPS.
13. Data Sharing
Personal data and technical data are not sold and are not shared with third parties for commercial purposes.
Data will only be disclosed where legally required or where necessary to establish, exercise, or defend legal claims.
14. Data Retention
Personal data and technical records are stored only as long as necessary for the purposes described in this Privacy Policy.
As a general rule, stored data may be retained for up to 5 years. Data may be deleted earlier if it is no longer required, if storage capacity or operational reasons make earlier deletion necessary, or if a valid legal request for deletion applies.
The exact retention period may therefore vary depending on technical and operational requirements and on the actual use of the service.
15. Backups
Stored data may also be included in backup copies created for security and recovery purposes. Deletion of data from live systems may therefore not immediately result in deletion from all backup copies, which may instead be removed in the normal backup rotation cycle.
16. Data Security
Reasonable technical and organizational measures are taken to protect personal data and technical records against unauthorized access, loss, misuse, or alteration.
However, please note that ECU data states and related raw binary data may currently be stored without encryption at rest.
Despite security measures, no internet-based service or storage system can guarantee absolute security.
17. Your Rights
Subject to applicable law, you may have the right to:
- Request access to your personal data
- Request correction of inaccurate data
- Request deletion of data where legally applicable
- Request restriction of processing
- Object to certain processing activities
- Withdraw consent at any time where processing is based on consent
- Lodge a complaint with a competent data protection authority
18. Data Access Requests Related to ECU Data States
Where technically feasible and where sufficient matching with a corresponding vehicle-related dataset can be established, users may request information about stored ECU data states associated with their vehicle.
19. Children
This service is not specifically directed to children.
20. Contact
If you have questions about this Privacy Policy or want to request information about your data, please contact:
21. Changes to This Privacy Policy
This Privacy Policy may be updated from time to time. The latest version will be published on this page with the corresponding effective date.