Privacy of this site
Last updated: August 2026
This page is about the site sosdae.com. The SOS DAE app has its own policy, different and more detailed, because it handles things the site does not — your location, on-site checks, reports.
What we don’t do
No profiling cookies, no behavioural analytics, no advertising, no social buttons loading third-party scripts.
The presentation pages and the map ask for no account and create none. The only restricted part is SOS DAE Management, the service for organisations responsible for defibrillators: if you don’t use it, nothing here changes for you.
What happens when you visit a page
The provider hosting the site records the request with your IP address, for technical and security reasons. It is log data, kept for a limited period and not used to profile you.
The presentation pages are static files: no code runs on the server to build them and no database is read.
The map section
The map reachable from this site is the same application as the app, and behaves the same way: your location, if you grant it, stays in the browser and is used to compute the distance to the defibrillators around you. For browsing alone it never leaves the device.
The map background comes from CARTO, an external tile provider, which in serving each tile receives the area you are looking at and your IP address. Address search, if you use it, goes through Nominatim at the OpenStreetMap Foundation, and defibrillator data comes from OpenAEDMap and the OpenStreetMap APIs.
These are requests your browser makes directly to those services: without them the map cannot be drawn, so the legal basis is our legitimate interest in making it work. If you’d rather not contact them, the map is the only page on the site that does — the others make no external requests.
The full detail, service by service, is in the policy inside the application.
If you confirm or report a defibrillator
This is the only thing the site really sends to a server of ours, and it’s worth explaining in full. Confirming an AED, saying the cabinet is empty or proposing a new one requires you to be on site: the app measures your position and transmits it together with the defibrillator’s to check the distance is plausible.
The server keeps nothing of your position. It is needed for an instant to compute how many metres separated you from the AED, and only that number is kept, rounded to the metre, along with the GPS accuracy. The coordinates end up in no table: that is a choice written into the database schema, not a promise.
A random device identifier travels with it, a number generated by the app that does not derive from the phone, contains nothing of yours and is not linked to an account — the app has none. It serves one purpose: counting three different people instead of the same person three times, because a correction only becomes public when several independent devices agree.
The legal basis is our legitimate interest in keeping accurate a map others will use in an emergency. Observations are kept for at most two years, after which they carry no weight and are deleted. You can cut the link whenever you like: “Forget this device”, inside the app, resets the identifier and from then on old observations can no longer be traced to your phone.
The data lands on Supabase, in the Frankfurt data centre. No table is readable from outside: everything goes through functions that accept one report at a time and never return the list of who reported what.
What stays saved in your browser
The site uses no cookies. The map saves a few things in the browser’s local storage (`localStorage`), which is a different matter: it is never sent to a server, ours or anyone’s, and stays on your device until you clear the site data.
It holds the language you chose, the last downloaded copy of the defibrillators — that’s what makes the map work with no connection — and, if you use the app, your training progress and the AEDs you unlocked.
These are all information strictly necessary for the service you asked for. That is why you won’t find a consent banner: the law requires it for tracking, not for letting a site remember the language you want to read it in. If we had anything unnecessary, that banner would be there.
Providers and transfers outside the European Union
The providers processing data on our behalf are appointed as processors and bound by contract: the provider hosting the site and keeping its technical logs, and Supabase (Frankfurt data centre) for the restricted area. The up-to-date list with names is available by writing to the address below.
Some services the browser contacts are based outside the European Economic Area, and by receiving the request they see its IP address: CARTO for the map background, Google Maps if you tap “Go” for directions — which also receives the coordinates of the chosen defibrillator, not yours. They are not processors acting on our behalf: they are services your browser calls directly, each with its own policy, linked from the legal page inside the app.
If you report the state of an AED through OpenStreetMap notes, that report becomes public on the OSM map, text included. That is how OpenStreetMap works, and it’s worth knowing before you write: don’t put anything in there you wouldn’t want read in public.
We don’t sell data, don’t pass it to advertising intermediaries and don’t use it to train automated systems. We do no profiling and no automated decision-making about you.
If you write to us
Enquiries about the management service arrive by email. We use what you write only to reply and, if you become a customer, to manage the relationship.
We don’t sign anyone up to a newsletter because they wrote to us once.
SOS DAE Management: the restricted area
Who processes the data: the controller named at the bottom of this page. What is processed: your account email and password (we never see the password, it reaches the provider already hashed), organisation name, sites, devices with make and model, expiry dates and the maintenance log.
Why: to deliver the service you asked for — performance of a contract. Not to profile you, not to sell you anything else, not to pass data to anyone.
Where: on Supabase, in a data centre in the European Union (Frankfurt). Each organisation sees only its own data, and the separation is enforced by the database: it does not depend on the interface.
For how long: as long as the account is active. Once the service ends, data is deleted on request; the maintenance log may be kept longer only where it is needed to demonstrate compliance, and in that case we tell you.
Payments: when the price list is published, collection will go through a certified external provider. No card data passes through or stays on our systems: we only record that the subscription is active and until when.
If one of your devices is linked to the public map, you receive the reports the community files on that AED. You receive the fact — “two people found the cabinet empty” — never the identity of whoever reported it: those people are anonymous to us too.
Deleting the account, and the one thing that remains
Anyone with an account can delete it from the app, without writing to anybody and without having to ask. The account, the observations and votes, and any proposals nobody had confirmed yet all disappear. Proposals already confirmed stay on the map but lose their author: they are points other people corroborated, and removing them would hurt anyone looking for a defibrillator — while the link to you, which is what the law protects, disappears anyway.
There is one exception, and it only concerns people who have been suspended. Publishing on the map is a write others will read in an emergency, and anyone using it to fill a city with points that don’t exist is suspended automatically for a period that grows if it happens again. If that person deleted the account and came back, they would start clean: deletion would become the easiest way to unblock yourself.
To prevent that we keep a one-way hashed fingerprint of the identity held at Google or Apple — not the email, not the name, not the content. It is a code from which no person can be recovered: it only serves to recognise that that identity had a suspension in force. It is kept for two years, then deletes itself.
If you have never been suspended, deletion leaves absolutely nothing, and that is the normal case.
Your rights
Articles 15 to 22 of the GDPR give you the right to access the data concerning you and obtain a copy, to have it corrected if wrong, to request its erasure, to ask that processing be restricted while a dispute is open, to receive it in a machine-readable format and have it transferred to another provider, and to object to processing based on legitimate interest.
Where processing is based on consent — today only for location, which you grant to the browser — you can withdraw it at any time, and withdrawing does not make what happened before unlawful. For location this is done from the browser or phone settings, without going through us.
To exercise them, write to privacy@sosdae.com, the controller’s contact given at the bottom of the page. We reply within a month, extended to three if the request is complex — in which case we tell you within the first month, explaining why. We charge nothing and don’t ask for identity documents if we can recognise you another way.
If you think something is wrong, you can lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it) or with the authority of the country where you live, and in any case go to court.
If this policy changes
The date at the top is that of the last change. If a change touches something substantial — a new purpose, a new provider, a transfer that wasn’t there before — we don’t just change the date: we flag it visibly before the change takes effect.
All of it in one table
The same things said above, in short: for each processing operation the purpose, the legal basis that allows it and how long the data stays.
| Purpose | Legal basis | Retention |
|---|---|---|
| Serving the site pages and keeping server logs | Legitimate interest — security and operation (art. 6.1.f) | Technical logs: a few days, then deleted |
| Drawing the map and searching an address | Legitimate interest — delivering the requested function (art. 6.1.f) | No retention on our side |
| Computing the distance to the nearest defibrillator | Consent, given to the browser and revocable (art. 6.1.a) | For the session only, on your device |
| Checking that whoever reports an AED is really on site | Legitimate interest — reliability of the map (art. 6.1.f) | Position is not stored: only the distance in metres remains |
| Counting distinct devices behind a report | Legitimate interest — stopping one person counting as three (art. 6.1.f) | Random identifier, two years from the last observation |
| Preventing a suspension from being dodged by deleting the account | Legitimate interest — integrity of a map used in emergencies (art. 6.1.f) | Suspended users only: hashed fingerprint, two years |
| Remembering language, offline data and progress | Technical storage necessary for the service | On your device, until you clear the site data |
| Replying to people who write to us | Legitimate interest — responding to a request (art. 6.1.f) | Two years from the last exchange |
| Managing the restricted-area account | Performance of a contract (art. 6.1.b) | While the account is active, then deleted on request |
Data controller
The party deciding why and how data is processed, and to whom requests should be addressed.
- Data controller
- Devox
- VAT number
- IT04801720279
- Contact
- privacy@sosdae.com
- Registered office
- Mestre, Venezia (VE) 30172