Privacy Policy — BAV Train Audit | collana solutions AG
collana solutions AG BAV Train Audit
Privacy Policy

Privacy Policy
BAV Train Audit

Effective: 26 June 2025 Last updated: 26 June 2025 Version 1.0.13 Package: ch.collanasolutions.bavtrainaudit

1. Overview

BAV Train Audit is a professional tool developed on behalf of the Swiss Federal Office of Transport (BAV — Bundesamt für Verkehr), Safety Monitoring Section (Sektion Sicherheitsüberwachung). It is designed exclusively for authorised BAV freight-train inspectors conducting operational inspections of freight trains.

The app is not a consumer application. It is distributed only to authorised personnel. This privacy policy describes what data the app processes, where it is stored, and how it is used.

2. Data Controller

Developer
collana solutions AG

The Swiss Federal Office of Transport (BAV) is the commissioning authority and may act as an independent data controller for inspection records generated using this app.

3. Data the App Processes

3.1 Data stored locally on the device

All data processed by the app is stored exclusively in a local SQLite database (bav_train_audit.db) and in device SharedPreferences. No data is transmitted to any remote server by the app itself.

Reference / master data (imported from BAV-supplied CSV files)

CategoryFields
Inspector (Auditor) Surname, first name, mobile phone number, e-mail address
Railway operating company (EVU) Company name, hotline phone, company e-mail, street address, postal code, city, contact person name, contact person e-mail and phone, BAV planning contact and e-mail
Train timetables Train numbers, routes, wagon counts, dates — no personal data
Stations Station names, country codes — no personal data
Error catalogue / corrective measures Technical codes and multilingual descriptions (DE/FR/IT/EN) — no personal data

Audit records (generated during inspections)

CategoryFields
Inspection record Train number, inspection date, start and end time, control station, auditor identifier, recipient e-mail address, free-text comments, completion status, e-mail-sent flag
Wagon data Wagon number, tare/net/gross weights, UN hazardous goods number, wagon keeper mark
Error entries Car owner, UN wagon identifier, error code details, corrective measure description, free-text comments

App settings (SharedPreferences)

A BCC e-mail address configured by the inspector for monitoring purposes.

3.2 Data the app does NOT collect

The app does not access or collect:

  • Location / GPS data
  • Camera or microphone input
  • Contacts
  • Browsing history or app usage analytics
  • Device identifiers (IMEI, advertising ID, etc.)
  • Crash or performance telemetry

4. How Data Is Used

All stored data is used exclusively to:

  1. Pre-fill inspection forms with the inspector’s and EVU’s master data.
  2. Record the results of freight-train inspections.
  3. Generate official BAV inspection protocol PDF reports.
  4. Generate CSV export files for administrative records.
  5. Compose and dispatch inspection reports by e-mail to the railway operating company and the responsible BAV auditors.

5. Data Transmission

5.1 E-mail dispatch via the device’s e-mail client

When an inspector finalises an inspection, the app creates a PDF report and a CSV export file on the device and then opens the device’s installed e-mail client (e.g. Gmail, Outlook) via Android’s standard sharing intent. The app hands over the pre-composed e-mail — including recipient addresses (EVU company e-mail, auditor CC addresses, and an optional BCC address) and the attached report files — to the e-mail client.

The app itself does not open any network connection and does not transmit data to any server. The actual sending of the e-mail is performed entirely by the user’s e-mail client and its associated mail service, which are subject to their own privacy policies.

5.2 No analytics, no telemetry, no third-party SDKs

The app does not integrate any analytics, advertising, crash-reporting, or remote-monitoring service. No data is sent to third parties.

5.3 Android Auto Backup

The app declares android:allowBackup="true" in its Android manifest. Depending on the user’s device settings, Android may back up the app’s local database and preferences to the user’s Google Drive account as part of Android’s standard Auto Backup service. This backup is end-to-end encrypted and is controlled by the user’s Google account settings. Users who wish to prevent this should disable Auto Backup for the app or for the device entirely in the Android system settings.

6. File & Storage Access

The app requests the following storage permissions:

PermissionPurpose
READ_EXTERNAL_STORAGE / READ_MEDIA_* To allow the inspector to select BAV-supplied CSV master-data files from device storage for import
WRITE_EXTERNAL_STORAGE (Android ≤ 9) To write generated PDF and CSV report files to app-scoped storage before sharing

Generated files (PDFs and CSVs) are written to app-scoped external storage (Android/data/ch.collanasolutions.bavtrainaudit/files/) and are not accessible to other apps without the user explicitly sharing them.

7. Data Retention

Data remains on the device until the inspector manually deletes an inspection record within the app, or until the app is uninstalled. The app does not impose automatic retention periods. Inspectors and the BAV are responsible for defining record-retention policies in accordance with applicable regulations.

8. Security

  • All data is stored locally in a SQLite database on the device. The database is protected by the device’s standard Android security model (app sandboxing).
  • The database schema is version-controlled. Destructive migrations (which erase all local data) may occur on major version upgrades; users are advised to finalise and e-mail all pending inspection reports before updating the app.
  • No encryption-at-rest is applied at the application layer beyond what the Android operating system provides. Inspectors should use a device with screen lock and, where required by organisational policy, full-disk encryption enabled.

9. Data Subjects‘ Rights

The personal data stored in the app (auditor and EVU contact data) originates from BAV-supplied master-data files imported by authorised administrators. Data subjects (inspectors and EVU contact persons) may exercise their rights under applicable data protection law — including the right to access, correction, or erasure — by contacting:

  • collana solutions AG at app.csag@collana.com (for app-level data handling questions), or
  • Swiss Federal Office of Transport (BAV) as the commissioning authority and data owner.

The app and its data processing are subject to the Swiss Federal Act on Data Protection (nDSG / LPD), in force since 1 September 2023. Where the app is used in a European context, the EU General Data Protection Regulation (GDPR) may additionally apply.

10. Children’s Privacy

This application is a professional tool intended exclusively for adult, authorised railway inspectors. It is not directed at children under the age of 16, and the developer does not knowingly collect personal data from children.

11. Changes to This Policy

Any material changes to this privacy policy will be reflected in an updated version published with the corresponding app release. The „Last updated“ date at the top of this document will be revised accordingly.

12. Contact

For questions or concerns regarding this privacy policy or the handling of personal data:

Developer
collana solutions AG
de_DEDE
Cookie Consent with Real Cookie Banner