Privacy Policy
Last updated: March 2026
We are pleased about your interest in our mobile application "SGF Discount App" (hereinafter "App"). The protection of your personal data is important to us. Below we inform you in detail about the collection, processing, and use of your data when using our App in accordance with the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG).
1. Controller
The controller within the meaning of the GDPR is:
Elektro-Großgeräte & Ersatzteilzentrale S.G. Fridriszik GmbH
Im Buttendicksfeld 5
46485 Wesel
Germany
Tel.: +49 (0) 281-56001
Fax: +49 (0) 281-56005
E-Mail: sgf.frank.becker@gmail.com
Website: www.ersatzteilhimmel.de
Managing Director: Barbara Fridriszik
Commercial Register: Local Court Duisburg
Registration Number: HRB 11204
VAT ID: DE186028514
2. Scope of data protection
This privacy policy informs you about the type, scope, and purpose of the collection and use of personal data within our App. Personal data is information relating to an identified or identifiable natural person.
3. What data we collect
3.1 Registration data (new registration)
When you register via the App, we collect:
- Salutation
- First name
- Last name
- Street address and house number
- Postal code
- City
- E-mail address
Legal basis: Art. 6(1)(b) GDPR (contract performance) – data is collected to set up and manage your customer account.
3.2 Sign-in data (existing account)
When you sign in with an existing account, we use:
- E-mail address
- Document number (from an existing invoice)
Legal basis: Art. 6(1)(b) GDPR (contract performance).
3.3 Device-related data
To ensure App functionality, we collect:
- Device ID: The Android ID on Android, or identifierForVendor on iOS. This is used to uniquely link your device to your customer account.
- Firebase Cloud Messaging token (FCM token): A unique identifier assigned by Google Firebase Cloud Messaging to deliver push notifications to you.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest) – unique device identification is necessary to correctly provide your personal discount information.
3.4 Usage data
During use of the App, the following data is processed:
- Balance: Your current balance is retrieved from the server and displayed.
- Purchases/invoices: An overview of your past purchases is displayed.
- Offers and promotions: Information about current discount campaigns and promotional offers.
Legal basis: Art. 6(1)(b) GDPR (contract performance).
3.5 Locally stored data
The App stores certain data locally on your device using "SharedPreferences" (a local key-value store). This data does not leave your device and includes:
- Customer number (UserID)
- E-mail address and document number (for automatic sign-in)
- Profile data (name, address)
- Selected client
- Notification history (title, text, and time of received push notifications)
This local data can be deleted at any time via the delete function in the App under "Profile & Settings".
4. Purpose of data processing
We process your data for the following purposes:
| Purpose | Description |
|---|---|
| Account management | Setting up, maintaining, and managing your customer account. |
| Discount code provision | Generating and displaying your personal discount barcode. |
| Balance display | Retrieving and displaying your current balance. |
| Purchase overview | Displaying your previous purchases/invoices. |
| Push notifications | Information about offers, promotions, and relevant news. |
| Customer notifications | Information about the status of ongoing orders (e.g. repair progress, pick-up readiness). |
| Offers and promotions | Displaying current discount campaigns and promotional offers. |
5. Data recipients and third-party services
5.1 eXODA API (App backend)
Your registration, sign-in, and usage data is transmitted via an encrypted HTTPS connection to our backend server (app.exoda.de). This server processes and stores your customer data to provide App functionality (account management, balance, invoices, offers).
Data transfer: All data is transmitted exclusively encrypted via HTTPS.
5.2 Firebase Cloud Messaging (push notifications)
For sending push notifications we use Firebase Cloud Messaging (FCM) by Google (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland). Firebase receives:
- A unique FCM token (device-bound push address)
- Device type (Android/iOS)
- Operating system information
Firebase processes this data to deliver push messages. Further information on data protection is available in the Google Privacy Policy.
Legal basis: Art. 6(1)(a) GDPR (consent) – push notifications are only sent if you have granted permission. You can withdraw permission at any time in your device settings.
Note on data processing: Google processes data in data centres in the EU and worldwide. Transfer is based on standard contractual clauses pursuant to Art. 46(2)(c) GDPR and/or the EU–US Data Privacy Framework.
6. Data sharing
We do not share your personal data with third parties, unless:
- it is necessary for contract performance (e.g. transmission to our backend server),
- you have expressly consented, or
- there is a legal obligation.
Your data is not sold. Your data is not used for third-party advertising purposes or shared with data brokers.
7. Data security
We take appropriate technical and organisational security measures to protect your data:
- Encryption in transit: All communication between the App and our server takes place exclusively over encrypted HTTPS connections (TLS/SSL).
- Local storage: Local data is stored in the protected app storage of the respective operating system (Android/iOS).
- Token authentication: Access to the server API requires a valid authentication token.
8. Retention periods
Your personal data is stored only for as long as necessary for the purposes for which it was collected:
- Account data: Stored for as long as your customer account is active.
- Locally stored data: Stored until deleted by you (via the delete function in the App) or until the App is uninstalled.
- Push notification ID: Deleted when you uninstall the App or withdraw push permission.
Statutory retention periods (e.g. tax retention periods of up to 10 years) remain unaffected.
9. Your rights as a data subject
Under the GDPR, you have the following rights:
| Right | Description |
|---|---|
| Right of access (Art. 15 GDPR) | You can request information about your stored data. |
| Right to rectification (Art. 16 GDPR) | You can request correction of inaccurate data. |
| Right to erasure (Art. 17 GDPR) | You can request deletion of your data, provided no statutory retention obligations apply. |
| Restriction of processing (Art. 18 GDPR) | You can request restriction of processing. |
| Right to data portability (Art. 20 GDPR) | You can receive your data in a structured, machine-readable format. |
| Right to object (Art. 21 GDPR) | You can object to the processing of your data. |
| Withdrawal of consent (Art. 7(3) GDPR) | You can withdraw a given consent at any time with future effect. |
To exercise your rights, please contact:
sgf.frank.becker@gmail.com
or by post to the address above.
10. Data deletion in the App
You can delete your locally stored data at any time directly in the App:
- Open the App and navigate to the "Profile" tab.
- Scroll down to the "Delete" section.
- Enable the slider and confirm the deletion.
All locally stored account data (customer number, e-mail, document number, profile data) will be irreversibly removed from the device.
If you additionally wish to have your data on our server completely deleted, please contact us by e-mail at sgf.frank.becker@gmail.com.
11. No automated decision-making
No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.
12. No third-party advertising
The App contains no third-party advertisements and uses no advertising SDKs. No advertising IDs are collected or shared with advertising partners.
13. App permissions
The App requests the following permissions:
- Internet access: Required for communication with the backend server and push notification service.
- Push notifications: To receive notifications about offers and promotions. You are asked for permission on first launch and can withdraw it at any time in your device settings.
14. Changes to this privacy policy
We reserve the right to update this privacy policy to reflect changes in the law or changes to the App or data processing. The current version is always available in the App and on this website. We recommend checking the privacy policy regularly.
15. Right to lodge a complaint with a supervisory authority
If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority. The competent supervisory authority is:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestr. 2-4
40213 Düsseldorf
www.ldi.nrw.de
16. Contact
For questions about data protection or to exercise your rights, please contact:
Elektro-Großgeräte & Ersatzteilzentrale S.G. Fridriszik GmbH
Im Buttendicksfeld 5
46485 Wesel
Germany
Tel.: +49 (0) 281-56001
E-Mail: sgf.frank.becker@gmail.com