Information on data processing in accordance with the GDPR – Last updated: April 2026
The protection of personal data is of great importance. The operator of this application takes the protection of your personal data very seriously and treats your personal data confidentially and in accordance with the statutory data protection regulations as well as this privacy policy. The processing of personal data always takes place in accordance with the General Data Protection Regulation (GDPR) and the applicable country-specific data protection provisions. By means of this privacy policy, we wish to inform the public about the nature, scope and purpose of the personal data we collect, use and process. Furthermore, data subjects are informed by means of this privacy policy of the rights to which they are entitled.
This privacy policy applies to all pages and sub-pages of this web application as well as to all associated services, unless expressly stated otherwise. We point out that data transmission over the internet (e.g. when communicating by e-mail) may have security gaps. Complete protection of data against access by third parties is not possible. The controller has taken technical and organisational measures to ensure an adequate level of protection for the personal data processed by it. Nevertheless, internet-based data transmissions are generally subject to security risks, so that absolute protection cannot be guaranteed. Every data subject is therefore free to transmit personal data to us by alternative means, for example by telephone.
This privacy policy informs you, in accordance with Art. 13 and Art. 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation, GDPR) as well as in accordance with § 25 of the German Telecommunications-Digital-Services-Data-Protection Act (TDDDG), about how and why we process your personal data when you visit or use our web application. Personal data is any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more specific characteristics.
The collection and processing of your personal data takes place exclusively for the purposes described below and on the basis of the respective legal bases stated in accordance with Art. 6 GDPR. No processing beyond this takes place unless you have given separate consent to this or there is a legal obligation for further processing. The usage data is collected in order to ensure the technical functionality of the application, to continuously improve usability and to enable statistical analyses of the use of the application. Processing for advertising purposes or disclosure to third parties for commercial purposes expressly does not take place. All collected data is processed and stored exclusively on servers within the European Union, unless expressly stated otherwise below.
Davud Kahriman
Karlsbader Str. 38
70839 Gerlingen
Germany
E-mail: support@dual-use-finder.com
We process personal data only insofar as this is necessary to provide this web application or you have expressly consented. The legal bases arise from the General Data Protection Regulation (GDPR).
This application is provided via GitHub Pages (GitHub Inc., 88 Colin P. Kelly Jr. St., San Francisco, CA 94107, USA). When the page is accessed, GitHub automatically records server log data, including IP address, browser type, date and time of access.
This data is stored by GitHub for a maximum of 30 days and then automatically deleted.
Legal basis: Art. 6 (1) (f) GDPR. Data is transferred to the USA on the basis of the EU standard contractual clauses. The privacy policy of GitHub applies.
This application stores functional data exclusively locally in your browser (localStorage and sessionStorage). This includes, in particular, imported regulatory data, UI settings, your quiz progress and the login status for authorised users. This data does not leave your device and is not transmitted to our servers.
| Storage entry | Purpose of storage | Storage duration |
|---|---|---|
| dualuse_db (localStorage) |
Stores the dual-use regulatory database locally in the browser for offline operation, the core function of the search mask and fast loading times. | Persistent / until deleted |
| dualuse_cache_ts (localStorage) |
Stores the timestamp of the last database update to detect outdated cache data and ensure up-to-date search results. | Persistent / until deleted |
| UI settings (localStorage) |
Stores the display settings chosen by the user (e.g. dark mode, compact view, language) in order to retain them on future visits. | Persistent / until deleted |
| Quiz progress (localStorage) |
Stores the current score and the questions already answered in the quiz integrated into the app, so that progress is not lost when the page is reloaded. | Persistent / until "Reset quiz" is clicked or the browser cache is cleared |
| dualuse_admin (sessionStorage) |
Stores the temporary authentication status (login) for access to internal admin and export control functions. | Until the browser tab is closed |
The legal basis for storage in your terminal device is § 25 (2) no. 2 TDDDG (strictly necessary storage). Insofar as personal data is processed in individual cases, this is done on the basis of Art. 6 (1) (f) GDPR. The specific legitimate interest is to ensure a high-performance, uninterrupted use of the core functions (offline database, quiz and admin login) of the web application.
You can delete this data manually at any time: in the menu under Settings → Admin mode → Database → Delete all data, via the Reset quiz button, or via the browser settings under "Clear website data".
This website uses the Google Tag Manager of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The Google Tag Manager is purely a management tool that does not itself set any cookies and does not create any independent user profiles. It serves exclusively to centrally integrate and control other services and tracking codes (such as our cookie banner and – after your consent – Google Analytics) within our website.
For technical reasons, when you access our website your browser establishes a connection to Google's servers in order to download the Tag Manager script. In doing so, your IP address is transmitted to Google and data may be transferred to the USA. This transfer is mandatory in order to deliver the legally required consent management (cookie banner) technically without errors.
The legal basis for the use of the Google Tag Manager is our legitimate interest in a technically flawless, secure and data-protection-compliant integration and management of website services pursuant to Art. 6 (1) (f) GDPR.
To manage your cookie consent, we use the Cookiebot CMP service of Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark.
Cookiebot logs your consent and stores it to fulfil the obligation of proof pursuant to Art. 7 (1) GDPR. The following data is processed in the process: anonymised IP address, date/time of consent, browser information, URL of the page. These records of consent are stored for 12 months.
Legal basis: Art. 6 (1) (c) GDPR (legal obligation to demonstrate consent). A data processing agreement (DPA) pursuant to Art. 28 GDPR has been concluded with Usercentrics A/S. Further information: Cookiebot privacy policy.
This application uses Google Analytics 4 of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics is activated exclusively after your express consent (cookie banner). Without your consent, no tracking whatsoever takes place.
In the event of your consent, the following data is collected: anonymised IP address, pages visited, time spent, browser type, device information, source of origin. This data is processed on Google's servers, possibly also in the USA, and is automatically deleted after 14 months by default.
IP anonymisation: In Google Analytics 4, IP anonymisation is activated by default. No complete IP address is stored.
Legal basis: Art. 6 (1) (a) GDPR (consent). A data processing agreement pursuant to Art. 28 GDPR has been concluded with Google. Further information: Google privacy policy.
Withdraw consent: You can withdraw your consent at any time by calling up the cookie banner again (link in the footer) or by deleting the stored cookies for this domain in your browser settings. The withdrawal does not affect the lawfulness of the processing carried out up to that point.
If you use our contact form, the data you enter (name, e-mail address, subject, message) is processed in order to handle your enquiry.
The form is technically processed via the Web3Forms service (operator: HackerWave LLC, USA). Your message is forwarded encrypted to our e-mail address via the Web3Forms API. Web3Forms acts purely as a technical transmitter (routing), does not permanently store transmitted data for its own purposes and deletes it after delivery. We ourselves delete contact enquiries after complete processing, at the latest after 6 months.
Legal basis: Art. 6 (1) (b) GDPR (initiation of a contract / processing of your enquiry) as well as Art. 6 (1) (f) GDPR (legitimate interest in communication).
Data is transferred to the USA on the basis of the EU standard contractual clauses. Further information: Web3Forms privacy policy.
Alternatively, you can reach us directly by e-mail: support@dual-use-finder.com
You have the following rights vis-à-vis us with regard to your personal data:
To exercise your rights, please contact: support@dual-use-finder.com
You also have the right to lodge a complaint with a data protection supervisory authority. Competent authority for Baden-Württemberg: State Commissioner for Data Protection and Freedom of Information Baden-Württemberg.
This privacy policy is currently valid and dated April 2026. Due to the further development of this application or because of changed legal or official requirements, it may become necessary to amend this privacy policy. The respective current version is always available at this URL.
This privacy policy has been compiled with the greatest possible care. Nevertheless, we cannot guarantee the completeness, accuracy and timeliness of all information. Changes in the legal framework, case law or technical circumstances may make it necessary to adapt this privacy policy.
Liability for external links: This privacy policy applies exclusively to our web application. We assume no responsibility for the data protection practices of linked external websites – in particular GitHub Pages, Google or Usercentrics. When you click on external links, you leave our application; the respective operator is responsible for the data protection provisions applicable there.
Reservation of changes: We reserve the right to change or update this privacy policy at any time with effect for the future, in order to adapt it to changed legal situations, official requirements or new functions of the application. The respective current version is always available at this URL. We recommend reading this privacy policy regularly in order to stay informed about the current state of data processing.