Privacy Policy · VentiLo
Version: 1.0 • Last updated: 9 July 2026
1. Data Controller
SOFTECH TOTAL ENVIRONMENTAL ACTION S.R.L.
VIA ROMA 243 - 10123 - TORINO (TO), Italy
Tax ID / VAT 12962980012
Privacy email: info@softech-team.com
Certified email (PEC): legal@pec.softech-team.com
2. Data Protection Officer (DPO)
As of the date of this policy, no DPO has been appointed, as the conditions of Art. 37 GDPR do not apply. If one is appointed, the relevant contact details will be published in this policy.
3. Scope
This policy applies to the VentiLo mobile app, which suggests when to ventilate your home by comparing the indoor conditions entered by the user with the weather forecast and outdoor air quality. The advice concerns temperature and humidity only: the app does not assess indoor air quality and provides no medical or health advice.
VentiLo runs entirely on the user's device: it requires no sign-up, has no form of authentication, and relies on no server operated by the Controller. The Controller never receives, stores, or can access any personal data of the app's users.
4. Categories of data processed and sources
- Location (optional, user-initiated): the user may grant when-in-use location permission or instead type a city name manually; the app is fully usable without GPS. Geographic coordinates, rounded to 3 decimal places (about 100 meters), are sent over HTTPS to the third-party weather service Open-Meteo (open-meteo.com) to fetch the forecast and air quality for that area; typed city searches are sent to Open-Meteo's geocoding service. The Controller never receives, stores, or logs location on any system of its own.
- Data stored locally on the device: preferences (indoor temperature and humidity entered by the user, chosen city, theme, onboarding completion state) are kept in the app's local storage and never transmitted. Uninstalling the app permanently deletes them.
- App updates (expo-updates): on cold launch the app checks Expo's update service (expo.dev, based in the United States) for a new version of the JavaScript bundle. The request transmits technical data (IP address, app runtime version, platform); no user or device identifiers and no location.
- Connectivity check: to distinguish a missing connection from a service outage, the app sends a request to Open-Meteo; this is the same processing described under "Location", with no additional data.
- App stores: distribution, crash statistics, and TestFlight beta feedback are processed by Apple and Google as independent controllers, under their own privacy policies.
No special categories of data (Art. 9 GDPR) are processed.
5. Purposes and legal bases
- Weather forecasts and ventilation advice
Purpose: obtain from Open-Meteo the forecast and air quality for the area indicated by the user, via GPS or a typed city.
Legal basis: processing necessary to provide the service requested by the data subject (Art. 6(1)(b) GDPR). - App updates and security
Purpose: keep the app current and secure via the expo-updates service.
Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR).
6. Processing methods and security measures
All communication with third-party services takes place over an encrypted channel (HTTPS/TLS). Data entered by the user stays in the device's local storage, protected by the operating system's isolation mechanisms.
7. Recipients
The Controller receives no data and has appointed no processors under Art. 28 GDPR: requests go directly from the user's device to the following recipients, which act as independent controllers under their own terms:
- Open-Meteo (open-meteo.com), weather and geocoding service: receives rounded coordinates or city names. Under its terms of service, its server logs (IP addresses, request URLs) are deleted within 90 days. Open-Meteo terms of service.
- Expo (expo.dev), app update service: receives the technical data of the update request. Expo privacy policy.
- Apple and Google: distribution through their respective stores, crash statistics, and beta feedback, under their own privacy policies.
8. Transfers outside the EU
Open-Meteo processes requests within the European Union. Expo's update service is based in the United States: the transfer of technical data takes place under the European Commission's adequacy decision on the EU-US Data Privacy Framework (Art. 45 GDPR), in which Expo participates. Certification details are available at www.dataprivacyframework.gov.
9. Retention period
- Controller's systems: no retention, because no server of the Controller exists.
- Local data: kept on the device until the app is uninstalled or its data is cleared.
- Open-Meteo technical logs: deleted within 90 days under the provider's terms.
10. No cookies, accounts, or tracking
VentiLo uses no cookies, requires no account, and contains no third-party analytics, advertising, tracking, or profiling.
11. Nature of data provision
No data provision is mandatory. The location permission is optional: the app is fully usable by entering a city manually.
12. Data subject rights
Under Arts. 15-22 GDPR, data subjects may exercise the following rights:
- Access (Art. 15): obtain confirmation of processing and a copy of their personal data;
- Rectification (Art. 16): correct inaccurate or incomplete data;
- Erasure (Art. 17): request the deletion of personal data;
- Restriction (Art. 18): request the restriction of processing;
- Portability (Art. 20): receive data in a structured, machine-readable format;
- Objection (Art. 21): object at any time to processing based on legitimate interest.
Requests may be sent to info@softech-team.com; the Controller will respond within one month. Since the Controller stores no personal data on its own systems, it may be unable to identify the data subject (Art. 11 GDPR); locally stored data can be deleted independently by uninstalling the app.
A complaint may also be lodged with the Italian supervisory authority, Garante per la protezione dei dati personali, Piazza Venezia 11 - 00187 Roma, www.garanteprivacy.it.
13. Automated decision-making
Ventilation advice is computed locally on the device from weather data and the values entered by the user. No profiling and no automated decision-making with legal or similarly significant effects under Art. 22 GDPR take place.
14. Children
The app is suitable for general audiences and does not knowingly collect personal data from children.
15. Updates to this policy
This policy may be updated from time to time. The current version is always available on this page.