Rovora Rovora TCD map ← Back to the map

Privacy Policy

Version 1.2 · 23 September 2026 · Replaces version 1.1 of the same date (added the local “last known location” entry) · Applies to the website and installed app published as “Rovora TCD map” (the “Service”)

Summary. We run an unofficial campus map for Trinity College Dublin. There are no user accounts and no analytics, and we do not sell personal data. Language, theme and favourites stay in your browser. Your location is used in your browser and is sent onwards only when you start the in-app walking directions or tap a Google or Apple Maps link. We ask for your consent before the map contacts any third party. The operator is established in Hong Kong, so information can be handled outside the European Economic Area in the limited ways described in section 8, and both EU and Hong Kong data protection law can apply to that handling.
Contents
  1. Who operates the Service, and how to reach us
  2. Not connected with Trinity College Dublin
  3. What this policy covers
  4. What we process
  5. Information stored on your device
  6. Location information
  7. Third parties that receive information
  8. International transfers, including Hong Kong
  9. Legal bases
  10. Your rights
  11. Complaints and supervisory authorities
  12. Hosting, logs and security
  13. How long we keep information
  14. Children
  15. No direct marketing
  16. Changes to this policy
  17. Contact

1. Who operates the Service, and how to reach us

The Service is published under the name Rovora and operated by Ruocent, established in Hong Kong. In this policy “we”, “us” and “our” mean that operator.

For the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) we are the controller of the limited processing described here. For Hong Kong’s Personal Data (Privacy) Ordinance (Cap. 486, “PDPO”) we are the data user.

Because the Service is offered to students, staff and visitors in Ireland and elsewhere in Europe, the GDPR applies to it under Article 3(2)(a) even though the operator is not established in the European Union. Where Article 27 GDPR requires a representative in the Union, a person based in Ireland is available to act as our representative, and correspondence sent to the address below is treated as correspondence with that representative.

Privacy contact: contact@ruocent.com. We answer privacy enquiries within one month, extended by up to two further months for complex requests as Article 12(3) GDPR allows.

We have not appointed a data protection officer. The processing described here is small in scale, is not systematic monitoring of individuals, and does not involve the special categories of data in Article 9 GDPR.

2. Not connected with Trinity College Dublin

The Service is an independent project. It is not operated, commissioned, endorsed, sponsored or approved by Trinity College Dublin, the University of Dublin, or any of their faculties, library services, estate or facilities teams. We have no relationship with the University as supplier, agent, partner or otherwise. Building names, room codes and similar references are used to identify locations and nothing more. The Terms of Use contain the full disclaimer.

3. What this policy covers

This policy describes how we handle information when you visit the Service, search its data, save favourites, use the in-app walking directions, or follow an outward link to Google Maps or Apple Maps.

It does not cover the third-party sites and applications we link to, including Google Maps, Apple Maps, OpenStreetMap and University websites. Once you leave the Service, the privacy notice of the site you reach applies. It does not cover any official University system either.

The Service is a reference tool. It is not intended for emergency use, for safety-critical navigation, or as a substitute for official signage, security instructions or accessibility guidance.

4. What we process

WhatDetailsWhere it goes
Search text and filters What you type in the search box and which category you select Processed in your browser only. Not sent to us or to anyone else.
Favourites Identifiers of the buildings, rooms or spaces you star Stored in your browser’s local storage on your device. Not sent to us.
Location Latitude, longitude and accuracy, as reported by your browser once you allow it Used in your browser to calculate distances and draw a route. Sent to the routing provider only while you use the in-app walking directions, and to Google or Apple only if you tap their link.
Last known location Your most recent position, kept for up to 30 minutes so that distances and directions still work when the browser is slow to provide a new fix Stored in your browser’s local storage on your device. Not sent to us. Cleared when you choose “Essential only” in the cookie settings, or when you clear your browser data.
Preferences Language, light or dark appearance, and your consent choice Stored in your browser’s local storage on your device.
Map images Requests for map tiles, which carry your IP address, a browser identifier and the coordinates of the tiles being viewed Sent to the OpenStreetMap tile servers after you consent, because the Service has no map imagery of its own.
Route requests Your coordinates and the destination coordinates Sent to the FOSSGIS routing service while you use in-app navigation and have consented.
Photographs and floor plans Requests for image files Loaded from the third-party locations where the source material is published, which exposes your IP address to that host.
Connection records IP address, requested file, time, browser identifier and error codes Recorded by the hosting environment that delivers the Service, for availability and security.

We do not build user profiles, do not combine information across websites, and have no means of identifying an individual visitor from the information above.

5. Information stored on your device

The Service sets no advertising cookies and uses no third-party tracking cookies. It stores a small number of values in your browser’s local storage and caches its own files so it can work offline. Under Article 5(3) of Directive 2002/58/EC, as implemented in Ireland by the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011, storing information on your device is allowed without consent where it is strictly necessary to provide the service you asked for, and otherwise requires your consent.

KeyWhat it holdsWhy
tcdnav.langLanguage code, for example en or zhRemembers the language you chose
tcdnav.themeauto, light or darkRemembers your appearance setting
tcdnav.favsInternal identifiers of starred placesRemembers your favourites
tcdnav.consentA version number, whether third-party loading is allowed, and the date you choseRecords your consent choice so you are not asked again, and keeps evidence of the decision
Service worker cachesCopies of the Service’s own pages, scripts, styles, data files, and map tiles you have already viewedMakes the Service open quickly and work offline

These values stay on your device until you clear the browser’s site data, remove the installed app, or reset the consent choice using “Cookie settings” in the Service. We set no cookies on our own domain. Clearing site data returns the Service to its first-use state.

You can block or delete this storage at any time in your browser settings. Blocking it does not stop you reading the map, but language, theme, favourites and consent choice will not be remembered between visits.

The Service does not track you across websites, so Do Not Track and Global Privacy Control signals have nothing to switch off here. No cross-site tracking takes place, so such signals do not change what is described in this policy.

6. Location information

Distances, the “near me” ordering and the walking directions all depend on knowing roughly where you are.

  • Your browser asks for permission before any location is read. If you refuse, the Service still works: you see no distances and cannot use the in-app route.
  • If you allow it, the coordinates stay in the memory of the page in your browser. There is no server of ours that could receive them.
  • If you tap Google Maps or Apple Maps, your browser navigates to that provider and the destination coordinates are placed in the link. From then on the provider’s own notice applies, including any location access it requests.
  • If you start the in-app walking directions, your coordinates and the destination coordinates are sent to the routing service described in section 7 so a route can be calculated along footpaths. The request contains coordinates only: no name, account or identifier. If your device is offline, the route is calculated on the device using a walking network packaged with the Service, and no request leaves your device.

We keep no location history, build no movement profiles, and disclose location to no one other than the routing provider you choose to invoke.

7. Third parties that receive information

A browser-based map cannot be drawn or routed without servers, so the providers below receive technical information when the corresponding part of the Service is used. Each entry states what is involved. We do not control their own processing.

ProviderPurpose and information involvedLocationTheir notice
OpenStreetMap Foundation — tile servers Supplying map images. Your IP address, browser identifier and the tiles requested are visible to the tile server. United Kingdom, with edge servers elsewhere osmfoundation.org/wiki/Privacy_Policy
FOSSGIS e.V. — public OSRM walking-route instance Calculating a walking route when you start in-app navigation. The request contains your coordinates and the destination coordinates. Germany fossgis.de/datenschutzerklaerung
Google Maps Contacted only if you tap the Google Maps button, which passes the destination coordinates to Google. United States and elsewhere policies.google.com/privacy
Apple Maps Contacted only if you tap the Apple Maps button, which passes the destination coordinates to Apple. United States and elsewhere apple.com/legal/privacy
Image hosts for photographs and floor plans Serving image files, which exposes your IP address to the host. Wherever the originating publisher stores them See the sources listed in section 11 of the Terms of Use.
Hosting provider for this deployment Serving the pages, scripts, styles and data files, keeping the connection secure and available, and keeping standard access logs that may include your IP address. Depending on the deployment, either the European Union or Hong Kong; see section 8. Provided by the operator of that deployment.

Information that never goes to a third party includes your search text, your filter choices, your favourites, and anything about your personal circumstances. The Service holds accessibility information about buildings, but never asks about or records your own needs or health.

8. International transfers, including Hong Kong

The operator is established in Hong Kong. The Service has no user database, no accounts and no server-side store of user information, which limits cross-border issues but does not remove them. The position is as follows.

8.1 What can leave the European Economic Area

  • Connection records at the hosting layer. Pages and data files are served from the deployment chosen for the Service. That deployment may sit in the European Union or in Hong Kong, and standard access logs (IP address, requested file, time, browser identifier, error codes) may be created there. Where those logs are created outside the EEA, including in Hong Kong, they are the only routine processing of personal data that crosses a border at our initiative.
  • Requests you trigger yourself. Loading map images contacts the OpenStreetMap tile servers in the United Kingdom; starting the in-app route contacts FOSSGIS in Germany; tapping Google Maps or Apple Maps contacts those providers in the United States; loading a photograph contacts whoever publishes it. These disclosures follow from your use of the relevant feature and are described in section 7.
  • Correspondence. If you email us, the message and your address are received in Hong Kong, where the operator is established.

8.2 Safeguards we rely on

  • Hong Kong has no adequacy decision from the European Commission. Where Article 46 GDPR applies to a transfer of personal data to Hong Kong, we rely on appropriate safeguards — in practice the standard contractual clauses approved by the European Commission — together with the technical measures described in this policy: no user accounts, no user database, minimal log content and short log retention.
  • The United Kingdom benefits from an adequacy decision and Germany is inside the EEA, so the tile and routing requests raise no transfer issue under the GDPR. Transfers to Google and Apple are governed by their own mechanisms, described in the notices linked in section 7.
  • We do not sell personal data and do not transfer personal data to any jurisdiction for marketing.

8.3 Hong Kong law

Because the operator is established in Hong Kong, its handling of personal data is also subject to the Personal Data (Privacy) Ordinance (Cap. 486). Under that Ordinance:

  • personal data must be collected for a lawful purpose connected with a function of the data user, be adequate but not excessive, and be used only for the stated purpose (Data Protection Principle 1);
  • data must be accurate and kept no longer than necessary (Data Protection Principle 2);
  • data must be used only for the purpose of collection or a directly related purpose unless you consent to another use (Data Protection Principle 3);
  • reasonable security measures must be applied (Data Protection Principle 4);
  • you may make a data access request and a data correction request, and may complain to the Privacy Commissioner for Personal Data (Data Protection Principles 5 and 6, and sections 18 to 22 of the Ordinance).

Section 33 of the Ordinance, which would regulate cross-border transfers of personal data out of Hong Kong, has not been brought into operation. If it is commenced in a relevant form, we will review our arrangements and update this policy. The direct marketing provisions, including section 35A, do not affect us because we do not use personal data for direct marketing.

Where the GDPR and the PDPO could both apply to the same processing, we apply the stricter requirement in practice, so information is handled to the standard that protects you most.

9. Legal bases

  • Consent (Article 6(1)(a) GDPR) — for map images, for sending coordinates to the walking-route service, and for any other optional feature that contacts a third party. You give this through the first-use notice, may refuse it and still search the data, and may withdraw it at any time using “Cookie settings”. Withdrawal does not affect the lawfulness of earlier processing.
  • Performance of what you asked for (Article 6(1)(b) GDPR) — for storing language, theme, favourites and your consent choice on your own device.
  • Legitimate interests (Article 6(1)(f) GDPR) — for operating, securing and maintaining the Service, including the access logs kept by the hosting environment. We have weighed those interests against your rights: the information involved is minimal, short-lived, and used neither for profiling nor for marketing.
  • Legal obligation (Article 6(1)(c) GDPR) — where we must keep or disclose information to comply with applicable law or a valid request from a competent authority.

10. Your rights

Under the GDPR you have the right to be informed, to access, to rectification, to erasure, to restriction, to object, to data portability, and to withdraw consent, together with the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

Under the PDPO you may make a data access request and a data correction request, and may complain to the Privacy Commissioner for Personal Data.

In practice we hold no personal data about you that could be retrieved: the Service has no accounts and no user database, and your preferences and favourites live only on your device. A request will therefore usually be answered by confirming that no such data is held and explaining how to clear the information in your browser. Requests and corrections concerning map content — a building name, a room code, opening hours, a photograph — are equally welcome and are handled as content corrections.

Write to contact@ruocent.com to exercise any of these rights.

11. Complaints and supervisory authorities

If you consider that your information has been handled unlawfully, you may complain to a supervisory authority.

Ireland — Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28
Also at Déisi House, 6 Earls Street, Portarlington, Co. Laois, R32 DY77
Telephone +353 57 868 4800 · Lo-call 1800 437 737 · dataprotection.ie

Hong Kong — Office of the Privacy Commissioner for Personal Data
The Commissioner handles complaints about data users under the PDPO. Current address, telephone numbers and complaint forms are published at pcpd.org.hk.

You may also complain to the supervisory authority in the country where you live, work, or where the alleged infringement took place, and you may seek a judicial remedy. Where a complaint concerns one of the providers in section 7, that provider is the relevant controller and the complaint is normally best directed there first.

12. Hosting, logs and security

The Service is delivered as a static website. The hosting environment processes the technical information needed to send files to your browser and may keep short-term access logs for availability, troubleshooting, abuse prevention and security. Those logs are kept only as long as needed for those purposes, then deleted or aggregated.

Requests are served over HTTPS where the deployment is configured with a certificate. Because the Service keeps no user database, the main risk we address is interference with the delivered files, which HTTPS protects against. We apply the technical and organisational measures appropriate to that low level of risk. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

13. How long we keep information

  • On your device: language, theme, favourites and consent choice remain until you clear them.
  • Route requests: we keep none; the routing provider’s retention is described in its own notice.
  • Hosting logs: kept only as long as needed for security and availability, then deleted or aggregated.
  • Email correspondence: kept as long as needed to deal with the matter and to evidence compliance, then deleted. We add you to no mailing list.

14. Children

The Service is a general-audience campus map and is not aimed at children. In Ireland the digital age of consent for information society services is 16. We do not knowingly process the personal data of children below that age, and no account or profile exists in any case. If you believe a child has provided personal data to us, write to us and we will delete it.

15. No direct marketing

We do not use your information for direct marketing, send no newsletters, and give no personal data to others for marketing. No consent under section 35A of the PDPO or Article 21(2) GDPR is therefore sought or needed.

16. Changes to this policy

We update this policy when the Service or the law changes. The version number and date at the top of the page identify the current text. If a change materially affects how third-party information is handled, we will ask for your consent again rather than rely on your earlier choice.

17. Contact

Rovora — operated by Ruocent (Hong Kong)
Email: contact@ruocent.com

Use this address for privacy requests, content corrections, accessibility feedback, and licensing or takedown questions. Where a request concerns material published by someone else, we pass it on where appropriate and, on request, remove the material from the Service.

Rovora TCD map · Privacy Policy v1.1 · 23 September 2026 · The English text governs.
Independent project operated by Ruocent (Hong Kong). Not connected with Trinity College Dublin.

Back to the map · Terms of Use · contact@ruocent.com