Skip to content
UDI Compass

Privacy notice

UDI Compass (https://udicompass.eu). Text version 2026-10-04.

This notice explains how the publisher processes personal data (Articles 13 and 14 GDPR). Regulatory identifiers such as a UDI-DI are not personal data by themselves.

Download a plain-text copy

Controller

Snoeters Software, a Dutch sole proprietorship (eenmanszaak), is the controller. Chamber of Commerce (KVK) 42165643. Postal address: Zinkstraat 24 Unit C6102, 4823 AD Breda, Netherlands. Privacy contact: privacy@snoeterssoftware.nl (Article 13(1)(a); delivered to the same organisation as info@snoeterssoftware.nl).

No data protection officer is appointed (Article 37 is not triggered for this solo controller). No Article 27 representative is required: the controller is established in the EEA. Supervisory authority: Autoriteit Persoonsgegevens (https://www.autoriteitpersoonsgegevens.nl/).

Account and sign-in

Purpose: create and secure your account. Data: email, magic-link token, account id, and login timestamps. If you choose Google, Google authenticates you and we store the link to that sign-in. If you choose Microsoft, Microsoft authenticates you and we store the link to that sign-in. We do not ask you to invent a password. Legal basis: contract (Article 6(1)(b)); login security is legitimate interests (Article 6(1)(f)). Retention: for the life of the account. After you delete the account we remove the email immediately and delete the remaining anonymised account row after 30 days. Recipients: our EU host, where Better Auth stores the account in our own database. Google only if you use Google sign-in (Google is then an independent controller for that sign-in). Microsoft only if you use Microsoft sign-in (Microsoft is then an independent controller for that sign-in).

Inventory scanner

Your spreadsheet never leaves this device. We only look up the UDI numbers we detect.

Purpose: look up UDI numbers you choose to check, and optionally save that list. Data we may receive: UDI-DI and Basic UDI-DI values, a line index (the row number in your file, not the spreadsheet), and a label if you save an inventory. The file stays in your browser. Supplier names, quantities, prices, patient names, and staff names are not the payload. Legal basis: contract (Article 6(1)(b)) when you are signed in; a scan that does not create an account is not stored as a customer file. Retention: a one-off scan is not kept as your file. A saved inventory is identifiers plus your label until you delete it or delete the account. Recipients: our EU host. A certificate-status report (PDF) is generated when you ask for it and downloaded to your device.

Do not send special-category data (Article 9), including patient names, staff names tied to a device, or other health data. A hospital customer does not give us a basis to process that data. We do not use identifier lists to train models. A future server-side parse of the full file would be a new purpose and would be described here before it starts.

Paid plans

Purpose: provide the plan you buy and keep tax records the merchant must keep. Data we store: email, plan, and Paddle customer id. Paddle collects checkout data (which can include country and a business VAT identification number) as an independent controller, not as our processor for the account database. Legal basis: contract (Article 6(1)(b)) for access; Paddle’s tax duties are its legal obligation (Article 6(1)(c)). Retention: we keep the plan link for the life of the account. Paddle keeps invoices under its own notice (https://www.paddle.com/legal/privacy). We do not store your card number. Records we must keep for tax stay for the statutory period (typically 7 years) and do not include the card.

Email we send

Purpose: magic-link sign-in, the alerts or billing messages you asked for, and one email when Watch and API subscriptions open if you ask for it. Data: email address and message type. We do not run a marketing list. That opening email is a single message. Legal basis: contract (Article 6(1)(b)) for sign-in, alerts, and billing; consent (Article 6(1)(a)) for the opening email. While subscriptions are closed, a new account is set to receive that email, and you can turn it off on the account page before it is sent. A visitor can enter an email on the pricing page for the same email. Retention: we keep the address until the email is sent or you withdraw. After it is sent we keep the address so we do not send a second one, until you delete the account or ask us to erase it. We do not keep a separate copy of every message; the email provider may keep delivery logs under its own policy. Recipients: Resend (transactional email).

Cookies and similar storage

We use only strictly necessary storage to keep you signed in and to secure the site (a session cookie, and any security cookie the sign-in library sets for that session). We do not use advertising, analytics, or live-chat cookies. You can block cookies in your browser; the Service may then be unable to maintain a session.

Legal basis: contract (Article 6(1)(b)) and legitimate interests in keeping the session intact (Article 6(1)(f)). Under the ePrivacy rules this storage is strictly necessary, so we do not show a consent banner and we do not load a consent tool. Analytics and other non-essential trackers stay off.

Security

Purpose: keep the Service available and stop abuse. Data: IP address, user-agent, and rate-limit counters. A sign-in session may store IP address and user-agent until the session ends or you delete the account. Legal basis: legitimate interests (Article 6(1)(f)). Retention: session fields end with the session; rate-limit counters last only as long as needed to enforce the limit and not more than 90 days. Recipients: our EU host.

Recipients

  • Hetzner Online GmbH — hosting and the application database, including accounts — Germany (EU).
  • Paddle — merchant of record for the purchase — independent controller — https://www.paddle.com/legal/privacy.
  • Resend — transactional email — established in the United States.
  • Migadu — mailbox for privacy@snoeterssoftware.nl and info@snoeterssoftware.nl.
  • Google — only if you choose Google sign-in — independent controller for that authentication.
  • Microsoft — only if you choose Microsoft sign-in — independent controller for that authentication.

We do not use an analytics vendor, an advertising network, a live-chat tool, or an error tracker. We do not sell personal data.

Transfers outside the EEA

The application database stays in the EU (Germany). Resend processes message delivery from the United States. Where a provider processes personal data outside the EEA, the transfer uses that provider’s Standard Contractual Clauses or an adequacy decision (including the EU–US Data Privacy Framework where the provider is certified), as applicable to that provider. Paddle’s own notice describes where it processes payment data.

Your rights

You may ask for access, rectification, erasure, restriction, portability, and, where the basis is legitimate interests, objection. You may also lodge a complaint with the Autoriteit Persoonsgegevens (https://www.autoriteitpersoonsgegevens.nl/).

Erasure of an account you can do yourself at https://udicompass.eu/app/account. That removes your email, ends the session, deletes watches and saved inventories, revokes API keys, detaches search logs from the account, and removes an address stored for the one email when subscriptions open. The anonymised account row is deleted after 30 days. For access, rectification, restriction, portability, or objection, email privacy@snoeterssoftware.nl. We reply within 30 days.

These rights do not cap compensation under GDPR Article 82. The Terms do not cap that right either.

Children

The Service is for professional use. We do not knowingly create an account for anyone under 16. If you believe we have, email privacy@snoeterssoftware.nl and we will delete it.

If something goes wrong

If a personal-data breach is likely to risk your rights and freedoms, we notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware, unless the breach is unlikely to result in a risk. If the risk is high, we tell affected people without undue delay. A weekend or a public holiday does not pause that clock.

Changes

The current notice is at https://udicompass.eu/legal/privacy. A plain-text copy you can store is at https://udicompass.eu/legal/privacy/download. The version date is 2026-10-04.