Legal
OverviewTerms of ServicePrivacy PolicyData Processing AgreementData and SecurityFrequently asked questions
Go to milmap.nl →

On this page

  • 1. Controller and contact details
  • 2. Scope of this privacy policy
  • 3. Which personal data we process
  • 4. Purposes of the processing
  • 5. Legal bases for the processing (Art. 6 GDPR)
  • 6. Location data
  • 7. End-to-end encrypted chat and chat metadata
  • 8. Retention periods
  • 9. Recipients and sub-processors
  • 10. Transfers outside the EEA
  • 11. Cookies
  • 12. Security
  • 13. Your rights as a data subject
  • 14. Minors
  • 15. Right to lodge a complaint with the Dutch Data Protection Authority
  • 16. Changes to this privacy policy
Overview / Privacy Policy

Privacy Policy

Effective 11 July 2026

MilMap attaches great importance to the protection of your personal data. In this privacy policy we explain which data we process, for what purpose and on which legal basis, how long we retain it and which rights you have — fully in accordance with the General Data Protection Regulation (GDPR).

Contents
  • 1. Controller and contact details
  • 2. Scope of this privacy policy
  • 3. Which personal data we process
  • 4. Purposes of the processing
  • 5. Legal bases for the processing (Art. 6 GDPR)
  • 6. Location data
  • 7. End-to-end encrypted chat and chat metadata
  • 8. Retention periods
  • 9. Recipients and sub-processors
  • 10. Transfers outside the EEA
  • 11. Cookies
  • 12. Security
  • 13. Your rights as a data subject
  • 14. Minors
  • 15. Right to lodge a complaint with the Dutch Data Protection Authority
  • 16. Changes to this privacy policy

1. Controller and contact details

MilMap is an online mapping, navigation and location platform (web/PWA and app) operated by Onavan B.V., established in the Netherlands and trading under the name "MilMap" (hereinafter "MilMap" or "we"). MilMap is the controller within the meaning of the General Data Protection Regulation (GDPR) for the personal data processed through the platform.

In this privacy policy we explain which personal data we process, for what purpose, on which legal basis, how long we retain it and which rights you have. Together with the Terms of Service, the Data Processing Agreement and the Data & Security document, this policy forms the legal framework under which MilMap is provided.

For general questions you can contact us at support@milmap.nl. For questions about privacy, the processing of your data or exercising your rights, please contact privacy@milmap.nl.

2. Scope of this privacy policy

This privacy policy applies to any use of MilMap: the website, the PWA, the mobile app, the APIs and all related services.

MilMap is aimed at, among others, military personnel, SAR and emergency services, and outdoor, trail running, survival and expedition users. With MilMap you can, among other things, search locations, plan routes, navigate, share and manage maps, mark locations, consult MGRS grid coordinates, calculate bearings, share your live location, view weather and elevation information, manage missions and teams and send messages via an end-to-end encrypted chat.

The processing of personal data carried out through third-party map and API services is, in addition to this policy, also subject to the privacy policy of the relevant party. See the sections Recipients and sub-processors and Transfers outside the EEA.

3. Which personal data we process

MilMap processes only the personal data necessary to provide and secure the service. We distinguish the following categories.

Account data (required for an account):

  • first and last name;
  • email address;
  • password, stored exclusively as an irreversible hash (bcrypt) — never in readable form;
  • date of registration;
  • subscription type and payment status.

Usage data:

  • routes, waypoints, maps, markers, missions and reports created by you;
  • import and export history (file formats and timestamps);
  • search history of location searches (stored locally in your browser, not transmitted to our servers).

Location data (optional, only with consent):

  • GPS position during active navigation or live location sharing. See the Location data section.

Technical and device data:

  • IP address (anonymised after 24 hours);
  • browser and device type;
  • session and log data.

Chat and communication data:

  • the content of chat messages is end-to-end encrypted and cannot be read by us (see the End-to-end encrypted chat section);
  • we process limited chat metadata, such as the existence of a conversation, the participants and timestamps, in order to deliver messages.
We do not process special categories of personal data (such as data concerning health, religion or political opinions) and ask that you do not share such data with us.

4. Purposes of the processing

MilMap processes personal data for the following purposes:

  • Service provision: offering, maintaining and improving the MilMap application and its mapping, navigation and location features;
  • Account and subscription management: registration, login, processing of subscriptions and invoicing;
  • Communication: responding to support requests and sending transactional emails (such as password resets and invoices);
  • Security and fraud prevention: detecting, preventing and investigating misuse, malfunctions and security incidents;
  • Service improvement: anonymised or aggregated usage statistics to improve functionality and performance;
  • Compliance with legal obligations: including the statutory retention obligation for invoices under tax law.

MilMap does not send commercial newsletters unless you have given explicit consent. Transactional emails (such as payment confirmations and password resets) are always sent, regardless of your marketing preferences.

MilMap never uses your personal data — and in particular your location data — for sale to third parties or for advertising profiling.

5. Legal bases for the processing (Art. 6 GDPR)

We process personal data only where a legal basis exists under Article 6 GDPR:

  • Performance of a contract (Art. 6(1)(b)): account and usage data necessary to provide the service to you;
  • Legitimate interest (Art. 6(1)(f)): technical logs, security monitoring and fraud prevention to protect the service and its users;
  • Consent (Art. 6(1)(a)): the processing of location data during navigation or live location sharing and optional communication preferences. You may withdraw consent at any time;
  • Legal obligation (Art. 6(1)(c)): retaining financial records and invoices in accordance with Dutch tax legislation.

Where we rely on legitimate interest, we have balanced our interests against your rights and freedoms. You may object to this processing; see the section Your rights as a data subject.

6. Location data

We process location data only after you have given explicit consent, and only for navigation, map features, route planning and the voluntary sharing of your live location.

Your GPS position during active navigation is in principle processed locally on your device and not stored on our servers, unless you save it yourself (for example as a track) or enable live location sharing. Live location sharing is always voluntary; you decide with whom you share your location and when you stop doing so.

You can withdraw location permission at any time via your device settings or the app.

GPS signals and map data may be inaccurate or incomplete. MilMap is not a certified, safety-critical or life-saving navigation system. You remain responsible at all times for situational awareness, terrain assessment and operational decisions.

7. End-to-end encrypted chat and chat metadata

MilMap's chat — including group conversations within missions and teams — is end-to-end encrypted (E2EE) by default. In doing so, we apply the principle of privacy by design and by default.

Messages are encrypted using sealed-box encryption based on modern, open cryptography (NaCl/libsodium). In practical terms this means:

  • messages are encrypted on the sender's device and only decrypted on the recipient's device;
  • MilMap stores only unreadable ciphertext and has no access to the content of your messages;
  • every user has a personal key pair; by default the private key remains on your own device;
  • group messages are sealed separately for each recipient, so that only the participants can read them;
  • you can optionally enable cross-device synchronisation with a personal PIN: your private key is then encrypted locally with a key derived from that PIN (Argon2id) and stored on the server exclusively as ciphertext. We do not know your PIN and therefore cannot decrypt that key.

Because we have no technical access to the content, we can only provide limited metadata (such as the existence of a conversation or timestamps) upon request by competent authorities — never the encrypted content. Further technical details can be found in the Data & Security document.

8. Retention periods

We do not retain personal data longer than necessary for the purposes for which it was collected, or as long as legally required:

  • Account data: up to 30 days after deletion of your account;
  • Routes, maps, missions and reports: up to 30 days after deletion of your account;
  • Invoice and payment data: 7 years, in accordance with the statutory tax retention obligation;
  • Technical logs: a maximum of 90 days;
  • IP addresses: anonymised after 24 hours;
  • Location data (live GPS): not stored on our servers, unless you save a track or live session yourself.

Logs and security data are deliberately retained for a short period. After the retention period expires, data is deleted or irreversibly anonymised.

9. Recipients and sub-processors

In order to provide MilMap, we engage a limited number of external service providers (sub-processors) that may process personal data on our behalf. We never provide more data than necessary. These are the following services:

  • Mapbox: map tiles and geocoding (converting place names into coordinates);
  • a weather service API: retrieving weather information for the selected location or route;
  • an elevation API: retrieving elevation information;
  • a hosting partner with servers in the EU: hosting of the application and database;
  • Stripe: processing of subscription payments. Payment details such as card numbers are processed by Stripe and never stored by MilMap;
  • an email/SMTP service: sending transactional emails.

Arrangements with all our processors are laid down in a data processing agreement in accordance with Article 28 GDPR. The Data Processing Agreement describes which data is processed, with which safeguards and under which conditions.

MilMap does not share personal data with advertising networks or data brokers and does not sell or rent data. We disclose data to government authorities only where we are legally required to do so.

10. Transfers outside the EEA

MilMap aims to process personal data within the European Economic Area (EEA). Our hosting takes place with a partner with servers in the EU.

Some sub-processors, such as providers of map, weather or payment services, may also process data outside the EEA. Where that is the case, we ensure appropriate safeguards in accordance with Chapter V GDPR, such as an adequacy decision of the European Commission or the Standard Contractual Clauses adopted by the Commission, supplemented where necessary with additional technical and organisational measures.

Details of the parties involved and the safeguards applied are set out in the Data Processing Agreement.

11. Cookies

MilMap uses only cookies and similar technologies that are necessary for the operation and security of the service:

  • functional cookies (necessary): for login status, session management and security. These are required for the application to work;
  • preference cookies: for remembering settings such as language and map style.

MilMap does not place tracking or advertising cookies and does not use third-party analytics cookies. Where consent is legally required for certain cookies, we request it in advance. Cookies from third-party map services are subject to the privacy policy of the relevant party.

12. Security

MilMap takes appropriate technical and organisational measures to protect personal data against loss and unlawful processing, including:

  • encrypted connections (TLS/HTTPS);
  • passwords stored as a secure hash (bcrypt);
  • end-to-end encryption of chat messages (see the End-to-end encrypted chat section);
  • need-to-know access control: employees only have access to data they require for their role;
  • regular security updates and monitoring for unauthorised access.

More information about our security architecture can be found in the Data & Security document.

No service can guarantee complete security; you remain responsible for the security of your own device and login credentials. In the event of a data breach posing a risk to your rights and freedoms, we will inform you and, where required, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) as soon as possible in accordance with the data breach notification obligation.

13. Your rights as a data subject

Under the GDPR you have the following rights with respect to your personal data:

  • Right of access: to request which data we process about you;
  • Right to rectification: to have inaccurate data corrected;
  • Right to erasure ("right to be forgotten"): to request that your data be deleted;
  • Right to restriction: to have the processing restricted in certain cases;
  • Right to data portability: to receive your data in a machine-readable format. You can export routes and maps yourself as GPX/KML via the app;
  • Right to object: to object to processing based on legitimate interest;
  • Right to withdraw consent: to withdraw previously given consent, without affecting the lawfulness of the processing carried out beforehand.

You can submit a request via privacy@milmap.nl. We will in principle respond within 30 days. To protect you, we may ask you to confirm your identity before acting on a request.

14. Minors

MilMap is intended for users aged 16 and over. If you are under 16, you may only use MilMap with the consent and involvement of a parent or legal guardian, in accordance with Article 8 GDPR.

We do not knowingly collect personal data from children under 16 without such consent. If we establish that this has nevertheless occurred, we will delete the data concerned as soon as possible. If you suspect that we have processed data of a minor without the required consent, please contact us at privacy@milmap.nl.

15. Right to lodge a complaint with the Dutch Data Protection Authority

If you believe that we do not handle your personal data with due care, we would appreciate it if you first contact us at privacy@milmap.nl so that we can look for a solution together.

In addition, you always have the right to lodge a complaint with the Dutch supervisory authority, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl). If you live or work in another EU member state, you may also contact the supervisory authority in that country.

16. Changes to this privacy policy

MilMap may amend this privacy policy from time to time, for example in the event of new features or changes in laws and regulations. The most current version is always available via the website and in the app; the date of the last change is shown at the top of this document.

In the event of material changes affecting your rights, we will inform you in advance, for example by email or via a notification in the app. We recommend that you consult this policy regularly.

This privacy policy and all processing by MilMap are governed by Dutch law; disputes will be submitted to the competent Dutch court. For further information, please refer to the Terms of Service, the Data Processing Agreement and the Data & Security document.

MilMapPrivacy by default.
Overviewmilmap.nl
© 2026 Onavan B.V. — MilMap. All rights reserved.