Privacy Policy

Last updated: April 2026

1. Data Controller

The data controller responsible for processing your personal data on this website is:

Ventve Mobile Screening GmbH
Zurich, Switzerland
Email: privacy@ventve.com

2. What Data We Collect

We collect the following personal data through this marketing website:

a) Form submissions

  • Waitlist form: Name, email address, city/canton, user type, consent timestamp
  • Partner inquiry forms (5 total): Company name, company size, city, contact name, email, message, partnership type
  • Investor inquiry form: Name, email address, organization, message

b) Technical data (automatically collected)

  • IP address
  • Browser user-agent string
  • Page visits (via Vercel Analytics, where configured in the Vercel dashboard)

3. Purpose of Data Processing

We process your data for the following purposes:

  • Waitlist management: To notify you when our mobile screening service launches in your city
  • Partnership inquiries: To evaluate and respond to partnership proposals from employers, insurers, hospitals, CROs, and technology partners
  • Investor relations: To process requests for our investor prospectus and related materials

4. Legal Basis

We process your personal data on the following legal bases (nFADP Art. 6; GDPR Art. 6(1)):

  • Consent (Art. 6(1)(a) GDPR): Form submissions -- you provide consent via the checkbox when submitting a form
  • Legitimate interest (Art. 6(1)(f) GDPR): Technical logs (IP address, user-agent) for website security and functionality
  • Consent: Email communications -- you opt in to receive updates when joining the waitlist or submitting an inquiry

You may withdraw your consent at any time by contacting us at privacy@ventve.com. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.

5. Third Parties and Service Providers

We use the following third-party services:

  • Vercel (United States): Website hosting. Your requests to this website are processed by Vercel's infrastructure, which may log IP addresses.
  • Google Fonts (United States): Web typography. When you load this website, your IP address is transferred to Google to retrieve font files.
  • Supabase (EU-West, AWS Ireland): Database service used to store form submissions. Data is stored in PostgreSQL databases in the EU-West-1 (Ireland) region and encrypted at rest.
  • Resend (United States): Transactional email delivery service used to send confirmation and notification emails related to form submissions.
  • Tailwind CSS CDN (United States, via Cloudflare): CSS framework loaded in the browser. Your IP address is transferred to Cloudflare when the page loads.
  • cdnjs (United States, via Cloudflare): JavaScript libraries (GSAP, ScrollTrigger, Three.js) used for website animations. Your IP address is transferred to Cloudflare when these load.
  • Unsplash (United States): Image CDN for supplementary clinical and workplace imagery. Your IP address is transferred to Unsplash when images from images.unsplash.com load. Safeguarded by SCCs.

Data Processing Agreements (DPAs) pursuant to Art. 28 GDPR are in place with all processors listed above, and we intend to self-host these CSS and JavaScript libraries in the future to further reduce third-party data transfers.

6. Cross-Border Data Transfers

The following cross-border data transfers may occur:

  • Vercel (United States): Website hosting and technical logs. Transfer safeguarded by Standard Contractual Clauses (SCCs).
  • Google Fonts (United States): IP address transfer for font loading. Covered by Google's data processing terms and SCCs.
  • Supabase (EU -- Ireland): Form submission data stored in EU-West-1. Ireland provides adequate data protection under the nFADP.
  • Resend (United States): Email delivery. Transfer safeguarded by Standard Contractual Clauses (SCCs).
  • German telemedicine physicians (planned): As part of future clinical operations, data may be shared with physicians in Germany. Germany provides adequate data protection under the nFADP.
  • Tailwind CSS CDN (United States, via Cloudflare): IP address transfer for stylesheet loading. Safeguarded by SCCs.
  • Unsplash (United States): IP address transfer for image loading from images.unsplash.com / plus.unsplash.com. Safeguarded by SCCs.
  • cdnjs (United States, via Cloudflare): IP address transfer for animation library loading. Safeguarded by SCCs.

7. Data Retention

  • Waitlist data: Retained until our service launches in your area, or a maximum of 24 months of inactivity, whichever comes first.
  • Partner and investor inquiries: Retained for 24 months after the last point of contact, then deleted unless an active business relationship exists.
  • Technical logs (Vercel): Automatically deleted after 30 days (Vercel default retention).

8. Your Rights

Under the nFADP (Art. 25-29) and GDPR (Art. 15-22), you have the following rights:

  • Right of access: You may request information about the personal data we hold about you
  • Right to rectification: You may request correction of inaccurate data
  • Right to erasure: You may request deletion of your personal data
  • Right to data portability: You may request a copy of your data in a structured, machine-readable format
  • Right to withdraw consent: You may withdraw your consent at any time
  • Right to object: You may object to the processing of your personal data based on legitimate interests

To exercise any of these rights, please contact us at privacy@ventve.com. We will respond to your request within 30 days.

9. Cookies and Local Storage

This website does not currently set any cookies. No localStorage or sessionStorage is used. No tracking cookies, analytics cookies, or advertising cookies are employed.

However, Google Fonts may transfer your IP address to Google when the website loads (see Section 5).

10. Data Storage and Security

Form submission data is stored in Supabase PostgreSQL databases located in EU-West-1 (Ireland). Data is encrypted at rest using Supabase's default encryption. Access to the database is restricted to authorized personnel only.

11. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Updates will be published on this page with a revised "Last updated" date. We encourage you to review this page periodically.

12. Scope

This Privacy Policy applies exclusively to the Ventve marketing website (ventve.com). Clinical data processing related to medical screenings and telemedicine consultations will be governed by a separate, more detailed privacy policy once clinical operations commence.

13. Children's Data

This website is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at privacy@ventve.com and we will delete such data.

14. Automated Decision-Making and Profiling

We do not use automated decision-making or profiling as defined by the GDPR and the nFADP.

15. Data Breach Notification

In the event of a personal data breach, we will notify the competent supervisory authority (the Swiss FDPIC) and affected individuals as required by applicable law (within 72 hours under the GDPR where applicable, and without undue delay under the nFADP).

16. Contact

For any questions or concerns regarding this Privacy Policy or your personal data, please contact:

Ventve Mobile Screening GmbH
Data Protection
Email: privacy@ventve.com