Legal
OverviewTerms of ServicePrivacy PolicyData Processing AgreementData and SecurityFrequently asked questions
Go to milmap.nl →

On this page

  • 1. Our security philosophy
  • 2. End-to-end encrypted chat
  • 3. Encryption in transit and at rest
  • 4. Access control and authentication
  • 5. Handling of location data
  • 6. Hosting, infrastructure and sub-processors
  • 7. Backups and retention periods
  • 8. Monitoring and logging
  • 9. Data breach procedure
  • 10. Responsible disclosure of vulnerabilities
  • 11. What you can do yourself
  • 12. Limitations and disclaimer
  • 13. Minimum age, your rights and contact
Overview / Data and Security

Data and Security

Effective 11 July 2026

MilMap is provided by Onavan B.V., established in the Netherlands, trading under the name "MilMap" (hereinafter "MilMap" or "we"). This document explains how we protect your data: from our security philosophy and the end-to-end encrypted chat to hosting, retention periods and our data breach procedure. It complements our Privacy Policy, Terms of Service and Data Processing Agreement.

Contents
  • 1. Our security philosophy
  • 2. End-to-end encrypted chat
  • 3. Encryption in transit and at rest
  • 4. Access control and authentication
  • 5. Handling of location data
  • 6. Hosting, infrastructure and sub-processors
  • 7. Backups and retention periods
  • 8. Monitoring and logging
  • 9. Data breach procedure
  • 10. Responsible disclosure of vulnerabilities
  • 11. What you can do yourself
  • 12. Limitations and disclaimer
  • 13. Minimum age, your rights and contact

1. Our security philosophy

At MilMap, security and privacy are not an afterthought but the foundation of everything we build. MilMap is an online mapping, navigation and location platform (web/PWA and app) used by, among others, military personnel, SAR and emergency services, and outdoor and expedition users. For these users in particular, the confidentiality of location and communication data can be of critical importance. That is why we follow two core principles from the GDPR as our guiding standard.

  • Privacy and security by design: security and data protection are built into every feature from the design stage, not added afterwards.
  • Privacy and security by default: the default settings are the most privacy-friendly ones. Features that share additional data (such as live location) are off by default and are only activated at your initiative.

In addition, we apply data minimisation: we only process the data we genuinely need to make a feature work, no more and no longer than necessary. What we do not collect cannot leak.

As a data controller within the meaning of the GDPR, Onavan B.V. is responsible for the data processed through MilMap. Exactly which personal data we process and for what purpose is described in our Privacy Policy.

2. End-to-end encrypted chat

The chat in MilMap is end-to-end encrypted (E2EE). This means messages are encrypted on the sender's device and are only decrypted again on the recipient's device. In transit and on the server, MilMap only stores unreadable encrypted text (ciphertext) and has no access to the content of your messages.

For this we use sealed-box encryption based on modern, widely audited open cryptography (NaCl/libsodium). A sealed box works as follows: a message is encrypted with the recipient's public key, using a temporary (ephemeral) key pair. Only the holder of the corresponding private key can open the message. This ensures the content is readable exclusively by the intended recipient.

How the keys work:

  • Every user has their own key pair: a public key and a private key.
  • The public key is shared so that others can encrypt messages to you; the private key remains on your device by default and never leaves it.
  • For group messages, the message is sealed separately per recipient: each group member receives their own sealed box, encrypted with his or her own public key.

Optional cross-device sync with a personal PIN:

  • If you want to use your chat on multiple devices, you can set a personal PIN for this purpose.
  • Your private key is then encrypted locally with a key derived from that PIN using Argon2id, a modern and deliberately compute-intensive key derivation function that is resistant to brute-force attacks.
  • Only the resulting ciphertext of your private key is stored on the server, so that another device can unlock it with your PIN.
  • MilMap does not know your PIN and does not store it. Without the PIN, no one — including us — can open the encrypted private key or your messages.
Because we do not know the content of your chat or your PIN, we cannot recover encrypted messages for you if you lose your PIN. Please store your PIN carefully.

3. Encryption in transit and at rest

In addition to the end-to-end encryption of the chat, we protect all data traffic between your device and our systems.

  • In transit: all communication between the MilMap app or website and our servers takes place over encrypted connections using TLS/HTTPS. This protects data against eavesdropping or tampering while it travels across the network.
  • At rest: data stored on our servers resides on secured, access-restricted systems. Where the infrastructure supports it, we apply encryption at rest, so that stored data is also protected at the storage level.

The end-to-end encrypted chat content is an additional layer of protection on top of the above: it is not only encrypted in transit, but also remains unreadable to MilMap at rest on our server.

4. Access control and authentication

Access to your account and to our systems is strictly controlled.

  • You sign in with your personal credentials. Passwords are never stored in readable form, but exclusively as a secure, irreversible hash value.
  • Access to data within MilMap is bound to authorisation: you only see and manage the maps, routes, missions and teams you are entitled to.
  • On our organisation's side, the principle of least privilege applies: only authorised persons are granted access to systems, and only to the extent required for their role.

We strongly recommend using a strong, unique password and not sharing your credentials. Section 11 explains what else you can do yourself to protect your account.

5. Handling of location data

Location data is at the heart of MilMap, but it is also the most sensitive data we process. We therefore handle it with restraint and transparency.

  • We only process location data with your consent and only for the feature you are using it for, such as searching locations, planning routes, navigating, placing markers, MGRS grid coordinates or bearing calculation.
  • Live location sharing is strictly voluntary and happens only at your own initiative. This feature is off by default and you decide whether, when and with whom you share your live location, for example within a mission or team.
  • We do not sell your location data and do not use it for advertising or for profiling for advertising purposes.

To display maps and perform certain functions, data is processed through external services (sub-processors), such as map tiles and geocoding. You can read more about this in section 6 and in our Privacy Policy.

Be aware that sharing your live location in operational or unsafe circumstances may carry risks. Only share your live location deliberately and with people you trust.

6. Hosting, infrastructure and sub-processors

MilMap is hosted with an EU hosting partner, with server hosting within the European Union. This keeps data within the protection of the European privacy regime.

To provide all features, we use a limited number of carefully selected external services (sub-processors). Agreements on data protection have been made with these parties. The main ones are:

  • Mapbox: map tiles and geocoding.
  • A weather service API: displaying weather information.
  • An elevation API: displaying elevation information.
  • An EU hosting partner: server hosting within the EU.
  • Stripe: processing payments and subscriptions.
  • An email/SMTP service: sending transactional email.

We do not sell location data and do not use it for advertising. For the relationship between MilMap and business customers that use MilMap as a processor, we refer to our Data Processing Agreement. An up-to-date overview of and explanation of the sub-processors can be found in our Privacy Policy.

7. Backups and retention periods

To prevent data loss and downtime, we regularly make backups of our systems. Backups are stored securely and are accessible only to authorised persons.

We do not keep personal data longer than necessary for the purposes for which it was collected, or as long as legally required. In practice this means, among other things:

  • We retain account data for as long as you have an active account.
  • After deletion of your account, your personal data is deleted or anonymised, except for data we are required to keep longer under a legal obligation (such as fiscal retention obligations for payment data).
  • Encrypted chat messages exist in backups exclusively as unreadable ciphertext as well; we cannot recover their content.

The specific retention periods per category of data are described in our Privacy Policy.

8. Monitoring and logging

We monitor our systems to detect failures, abuse and security incidents in a timely manner.

  • We keep technical log files, for example of server activity and security-relevant events, to detect problems and keep the service reliable and secure.
  • Logging is set up so that we record no more data than necessary for administration and security, in line with the principle of data minimisation.
  • Log files are protected and retained for a limited period, and are accessible only to authorised persons.

Monitoring is explicitly aimed at safeguarding the security and availability of the service, not at tracking the content of your communication. The content of the end-to-end encrypted chat remains unreadable even to our monitoring.

9. Data breach procedure

Despite all measures, a security incident can never be entirely ruled out. We are therefore prepared with a defined procedure.

  • Detection: through monitoring, reports and internal checks, we aim to identify incidents as quickly as possible.
  • Assessment and containment: in the event of a suspected data breach, we immediately assess its nature and scope, take measures to close the breach and limit damage, and document the incident.
  • Notification to the supervisory authority: if a data breach poses a risk to data subjects, we report it without undue delay and, where required, within 72 hours of discovery to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
  • Communication with data subjects: if a data breach is likely to result in a high risk to your rights and freedoms, we will inform you as a data subject, with information about what happened and what you can do.

Do you believe a data breach affecting MilMap has occurred? Please contact us as soon as possible at privacy@milmap.nl.

10. Responsible disclosure of vulnerabilities

We value the work of security researchers and users who help us make MilMap more secure. If you discover a vulnerability, we ask that you report it to us responsibly.

  • Send your report to security@milmap.nl, with sufficient information to reproduce the issue.
  • Give us a reasonable period to investigate and resolve the vulnerability before communicating about it publicly.
  • Do not exploit the vulnerability beyond what is necessary to demonstrate its existence. Do not delete, modify or view other people's data, and do not disrupt our services.

If you adhere to these principles and act in good faith, we will not take legal action against you in response to your report. We will keep you informed of the follow-up and appreciate you giving us the opportunity to resolve the issue first.

11. What you can do yourself

Security is a shared responsibility. There is a lot you can do yourself to protect your account and data.

  • Use a strong, unique password for MilMap and do not reuse it on other services. Consider a password manager.
  • Secure your device with a screen lock (PIN, password or biometrics) and keep your operating system and the MilMap app up to date.
  • Do not share your credentials or your chat PIN with anyone. MilMap will never ask you for your password or PIN.
  • Be careful when sharing your live location: do so deliberately, only with trusted people, and turn it off again when you no longer need it.
  • Sign out on devices you no longer use or that you hand over to someone else.
  • Stay alert to phishing: always verify that emails and links genuinely originate from MilMap.
If you lose your chat PIN, MilMap cannot recover your end-to-end encrypted messages. Store your PIN safely.

12. Limitations and disclaimer

We do everything we can to keep MilMap secure and reliable, but we are honest about the limits of that.

No system or method of data storage or transmission is one hundred percent secure. Although we take appropriate technical and organisational measures in line with the state of the art, we cannot guarantee absolute security. By using MilMap, you acknowledge this residual risk.

Safety and navigation disclaimer: GPS signals and map data may be inaccurate, outdated or incomplete. MilMap is not a certified, safety-critical or life-saving navigation system. Never rely blindly on the app: you remain responsible for your own situational awareness and for your operational and safety decisions. In critical situations, always use additional, reliable means and common sense.

The full liability provisions are set out in our Terms of Service.

13. Minimum age, your rights and contact

MilMap is intended for users aged 16 and over. If you are younger than 16, the consent and involvement of a parent or guardian is required, in accordance with Article 8 GDPR.

Under the GDPR, you have several rights regarding your personal data:

  • the right of access to the data we process about you;
  • the right to rectification of inaccurate data;
  • the right to erasure of your data;
  • the right to object to certain processing operations;
  • the right to data portability.

You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Contact:

  • General questions and support: support@milmap.nl
  • Privacy and GDPR-related questions, and reports of (suspected) data breaches: privacy@milmap.nl
  • Reports of security vulnerabilities: security@milmap.nl

The use of MilMap and this document are governed by Dutch law; disputes will be submitted to the competent Dutch court. This "Data and Security" document should be read in conjunction with our Privacy Policy, Terms of Service and Data Processing Agreement.

MilMapPrivacy by default.
Overviewmilmap.nl
© 2026 Onavan B.V. — MilMap. All rights reserved.