Privacy Policy
Last updated: February 2026
1. Data Controller
JAWD AI by Daniel Hammenfors is the data controller for personal data in VentiDoc. Contact: support@ventidoc.no
2. Data We Collect
We collect: - Account info: Name, email (via Google sign-in) - Company info: Company name, org number, address, phone - Professional info: F-gas certificate number - Customer data: Your customers' names, addresses, contact info (you are the data processor for your customers' data) - Work data: Work orders, installations, measurements, checklists - Photos: Nameplate scans and documentation photos - Usage data: Login times, feature usage (anonymized)
3. Purpose
Your data is used to: - Provide the VentiDoc service (offline field documentation, sync) - Manage subscription and trial period - AI assistant for technical support (optional, requires internet) - Customer service and technical support - Service improvement (anonymized statistics)
4. Legal Basis
- Contract (GDPR Art. 6(1)(b)): Service delivery - Consent (GDPR Art. 6(1)(a)): AI assistant, newsletter - Legitimate interest (GDPR Art. 6(1)(f)): Security, fraud prevention
5. Data Storage & Security
- Local storage: Data is stored first on your device (IndexedDB). You control this. - Cloud storage: When syncing, data is stored in Supabase (EU region). Encrypted in transit (TLS) and at rest. - AI data: Chat messages are sent to Cloudflare Workers AI for processing. No storage after response. - Access: Row Level Security (RLS) ensures only you see your data. VentiDoc owner has NO access to your customer data.
6. Your Rights
You have the right to: - Access: View all data we hold about you - Rectification: Correct inaccurate data - Erasure: Delete your account and all data - Data portability: Export data in machine-readable format - Object: Object to data processing - Withdraw consent: Where processing is based on consent Contact support@ventidoc.no to exercise your rights.
7. Third-Party Sharing
We share data with: - Supabase (processor, EU): Database and authentication - Cloudflare (processor): AI assistant and CDN - Google (authentication): OAuth sign-in - Stripe (payment): When upgrading to paid plan We NEVER sell your data.
8. Retention
Data is retained as long as you have an active account. Upon deletion, all data is removed within 30 days. Anonymized statistics may be retained.
9. Cookies
VentiDoc uses only functional cookies/localStorage for login, language, and theme. We do NOT use tracking cookies or third-party analytics.
10. Contact & Complaints
Contact us: support@ventidoc.no Complaints to the Norwegian Data Protection Authority: www.datatilsynet.no