Privacy Policy

VTP Inspector — iOS Application

Last updated: 8 July 2026
Effective date: 8 July 2026

1. Data Controller

The controller of your personal data is Soondle S.L. (hereinafter “Soondle” or “we”), a Spanish company with tax ID [NIF pending] and registered address at [Registered address pending].

You can reach us at soporte@soondle.com. For data-protection specific queries, please write to our Data Protection Officer at dpo@soondle.com.

2. What personal data we collect

VTP Inspector is a B2B tool for workshop technicians and vehicle inspection staff. The categories of data we process, and why:

  • Email address: used to authenticate your session via one-time password (OTP). We do not send commercial communications without your explicit consent.
  • Vehicle-inspection data: licence plate, VIN, EU homologation category (M1, N2, O3, etc.), GPS coordinates at the inspection point, and per-tire data (DOT code, dimension, manufacturing date, compliance status and detected damage).
  • Captured photographs: images of the DOT stamp on the tire sidewall and images of visual damage. These images are part of the vehicle's signed passport and are retained as evidence of the work performed.
  • Session and device data: access tokens (stored in the iOS Keychain), device identifier, iOS and client versions, IP address, and technical signals that Supabase Auth records for security and anti-fraud purposes.
  • Credit-wallet data: available balance, purchase history and per-scan debits. Card details are not processed by Soondle; they are handled by Stripe (see section 5).
  • Unreadable-tire reports: when you flag a tire as “unreadable” to the team, we process the photograph, the free-text description you provide, and the OCR metadata associated with the read attempt.
  • Technical and audit logs: each signed inspection produces a cryptographic record (Ed25519) containing a timestamp, the operator's identifier, and a canonical content hash. These records are immutable by design.

VTP Inspector does not collect contacts, calendars, health information, content from other apps or advertising identifiers. We do not perform profiling for third-party advertising.

3. Legal basis for processing

We process your data under the following legal bases of Regulation (EU) 2016/679 (GDPR):

  • Performance of a contract (Art. 6(1)(b) GDPR): almost all processing (authentication, inspection logging, cryptographic signing, credit-wallet management) is necessary to provide the service your workshop or employer has contracted.
  • Legitimate interest (Art. 6(1)(f) GDPR): platform security, fraud prevention, technical audit logs and service improvement. You may object to this processing through the channels in section 8.
  • Legal obligation (Art. 6(1)(c) GDPR): retention of documents that are relevant for accounting, tax and vehicle-inspection traceability under applicable regulations.
  • Consent (Art. 6(1)(a) GDPR): if we later enable commercial communications or additional features that require it, we will request your consent expressly and you will be able to withdraw it at any time.

4. How we use your data

  • Authenticate you and keep your session active securely.
  • Record each inspection, sign it cryptographically and generate the vehicle's digital passport.
  • Enable sharing of the signed passport with third parties you authorise, through short-lived links.
  • Charge credits consumed by each live decode and update your balance after a purchase on Stripe.
  • Manage unreadable-tire reports and the admin-team review workflow.
  • Notify you by email or inside the app of relevant events (e.g. when the team resolves one of your reports).
  • Prevent unauthorised access, moderate uploaded content (photographs) and meet our legal obligations.

5. Data processors and third parties

To deliver the service we rely on suppliers acting as data processors under GDPR-compliant contracts:

  • Supabase (Supabase Inc., USA with EU infrastructure): account storage, multi-tenant database, OTP authentication and real-time channels. Where sub-processing crosses borders we rely on Standard Contractual Clauses (SCCs).
  • Cloudflare (Cloudflare Inc.): content delivery network, edge worker hosting the public API, and web application firewall. Traffic is routed preferentially to European nodes.
  • Eines Vision (computer-vision provider): OCR decoding of the DOT stamp. Receives the tire image from our edge worker over mTLS and returns the structured result; receives no account or vehicle data.
  • Stripe (Stripe Payments Europe, Ltd.): payment processing and billing for credit top-ups. Card data is processed directly by Stripe under its own privacy policy.
  • Apple (Apple Distribution International Ltd.): app distribution via App Store and TestFlight. Apple applies its own privacy policy to installation and crash reports.

We do not sell your personal data to third parties under any circumstances. We only share information with public authorities when there is a binding legal requirement.

6. International transfers

Primary servers are located in the European Union. Where a processor (typically Supabase or Stripe) needs to handle data outside the European Economic Area, the transfer is safeguarded by the Standard Contractual Clauses approved by the European Commission (Decision 2021/914) and, where appropriate, by supplementary technical and organisational measures.

7. Retention periods

  • Account data: for as long as you have a contractual relationship with Soondle or with your workshop.
  • Signed passports and inspection images: for the full period legally required for technical vehicle inspections (typically between 5 and 10 years depending on jurisdiction). Once that period elapses the data is anonymised or deleted.
  • Accounting and billing records: six years, under Article 30 of the Spanish Commercial Code and applicable tax legislation.
  • Session tokens and technical logs: up to ninety (90) days from generation, unless a legal requirement dictates otherwise.
  • Accounts deleted at your request: we retain only the data strictly necessary to meet legal obligations or to defend against potential claims, appropriately segregated.

8. Your rights

You may exercise the following rights recognised by the GDPR at any time:

  • Access to your personal data (Art. 15).
  • Rectification of inaccurate data (Art. 16).
  • Erasure or “right to be forgotten” (Art. 17), subject to the exceptions provided by the regulation.
  • Restriction of processing (Art. 18).
  • Portability of the data you have provided to us (Art. 20).
  • Objection to processing based on legitimate interest (Art. 21).
  • Not to be subject to automated decisions producing legal effects (Art. 22). VTP Inspector does not make such decisions.

To exercise any of these rights, write to dpo@soondle.com stating the right you wish to exercise and attaching a copy of your national ID or equivalent document. We will reply within one month.

If you believe the processing does not comply with the regulation, you may lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es, or with the competent supervisory authority in your country.

9. Security

We apply reasonable technical and organisational measures to protect your data:

  • Encryption in transit with TLS 1.2 or above on every channel.
  • Session tokens stored in the iOS Keychain, protected by the device's Secure Enclave.
  • Database-level multi-tenant isolation via Row-Level Security (Supabase), so each workshop can only access its own inspections.
  • Ed25519 cryptographic signing of every passport, with public verification against a JWKS key service, to detect any tampering.
  • Anti-fraud and moderation filtering on images uploaded to the platform.
  • Immutable audit logging for sensitive actions.

10. Cookies and similar technologies

The iOS application does not use web cookies. When you access the “Buy more credits” section of your profile, the app opens an embedded Safari view (SFSafariViewController) against app.vtp.soondle.com/wallet. That view may set cookies that are strictly necessary for session management and for the Stripe payment flow. We do not use cookies for third-party advertising or analytics.

11. Minors

VTP Inspector is a professional B2B tool. It is not directed at persons under eighteen (18) years of age, and we do not deliberately collect data from minors. If we discover that data belonging to a minor has been provided, we will delete it.

12. Changes to this policy

We may update this policy to reflect legal, technical or operational changes. The version in force will always be published at this URL, with the last-updated date shown. Where a change materially affects how we process your data, we will notify you by email or through an in-app notice at least thirty (30) days in advance.

13. Contact

For any query about this policy or the processing of your personal data: