← Back to app
ENODEUS
NDT Inspection Technology · B2B Industrial Platform
Automatic translation powered by Google. The English version is the official, legally binding text.
Privacy Policy
How ENODEUS collects, uses, and protects your data
Last updated: July 1, 2026 · Version 2.0
This Privacy Policy should be reviewed by a qualified data-protection lawyer before production use, particularly because ENODEUS processes industrial inspection data that may be subject to confidentiality obligations under client contracts or NDAs.
1. Who we are
ENODEUS ("we", "us", "our") is an AI-assisted Non-Destructive Testing (NDT) and industrial inspection management platform operated by Maximiliano Olmos Sanchez. The platform serves three types of users: Inspectors (individual professionals), Managers/Jefes (team leads), and Companies/Empresas (organizations with subscription plans).
Contact: contact@enodeus.ch
2. Data we collect
2.1 Account and profile data
- Name, email address, and authentication credentials (via Google Firebase Authentication, including Google Sign-In).
- Optional profile info: company name, job title, phone, location, LinkedIn, website, profile photo.
- Professional NDT certifications (level, method, expiry date) stored in your profile.
- Organizational role: Inspector, Manager, or Company — stored locally and in your user profile.
2.2 NDT Inspection and report data
- Inspection images you upload for AI analysis (UV-A photographs, VT photos, etc.).
- Inspection parameters: NDT method (PT/MT/UT/RT/VT/ET/PAUT/TT/LT/Drone), applicable standard, material, equipment model and serial number, calibration date, procedure number, acceptance criteria, dwell times, temperatures, light intensity, humidity.
- Inspection results: final disposition, indication details, observations, digital signatures.
- AI-generated results: indications detected, affected area, processed images.
- Carbon and water footprint data you enter voluntarily (ESG reporting).
2.3 NDT Asset Traceability data NEW
- Asset records: Asset codes (e.g. ENO-UT-XX-00001), asset type, project name, material, size, location reference, and operational status.
- Inspection history: Per-asset inspection records linked to the inspector who performed them.
- Non-Conformance Reports (NCRs): NCR numbers, defect descriptions, severity classifications, corrective action assignments, and closure status.
- Corrective and Preventive Actions (CAPAs): Root cause analysis, corrective/preventive actions, due dates, and effectiveness verification.
- Trace logs: Append-only immutable audit trail of all events on each asset (creation, inspections, NCR creation, status changes). These logs cannot be deleted or modified — they are retained as part of the industrial audit record.
- QR codes: Each asset generates a unique QR code linked to its Firestore record. QR codes do not contain personal data — they contain only the asset identifier.
2.4 Company and organizational data NEW
- Company accounts: Company name, join code, owner UID, member UIDs (inspectors), and manager UIDs (jefes).
- Work Orders: Title, description, priority, deadlines, sender/recipient identifiers, module, status, and internal chat messages between team members.
- Work Groups: Group name, members, and linked company.
- Project Work Orders: Project assignments between Companies and Managers.
- Direct messages: Messages exchanged between inspectors and their managers within the platform.
2.5 Usage data
- Number of inspections and reports generated, for your statistics and optional ranking.
- Basic technical and access logs needed to operate and secure the service.
- Crash reports via Firebase Crashlytics (anonymized device and app state data).
3. How we use your data
- To provide the core service: analyzing images, generating reports, and managing NDT assets.
- To enable team collaboration: Work Orders, direct messages, group chats, and NCR/CAPA workflows between inspectors and managers.
- To maintain industrial traceability: immutable audit logs per asset, as required by NDT standards (ASME, ISO, EN, API).
- To create your dashboard, statistics, and (if shown) the global ranking.
- To send inspection reports to recipients you specify.
- To operate, maintain, secure, and improve the application.
- To communicate about your account, the service, or subscription billing.
4. Data shared within your organization
ENODEUS is a B2B platform. When you join a company as an Inspector or Manager, certain data becomes visible to authorized personnel within your organization:
- Your name and email are visible to the Company owner and your assigned Manager.
- Inspection results and NCRs you create on company assets are visible to your Manager and the Company owner.
- Work Orders sent to you are visible to the sender (Manager or Company).
- Direct messages are visible only to you and your Manager.
If you are an Inspector Freelancer (free plan), you do not belong to any company and your data is not shared with any third party within the platform.
5. AI model training (opt-in only)
We will only use your inspection images to train our AI models if you have given explicit, separate consent through the opt-in setting in your profile. This is voluntary and can be withdrawn at any time. When you opt in, identifying information (client name, site location, report metadata) is removed from images before use. If you do not opt in, your images are used solely to generate your own reports.
If your inspection images are subject to confidentiality agreements (NDAs), do not opt in to AI training without your client's authorization.
6. Legal basis
We process data under the Swiss nFADP and, where applicable, the EU GDPR. Our legal bases are: contract (to provide the service), consent (for optional features and AI training), legitimate interest (to secure and improve the service), and legal obligation (retention of industrial audit records).
7. Data sharing with third parties
We do not sell your personal data. We share data only with:
- Google Firebase: Authentication, Firestore database, Storage, Crashlytics, App Check.
- Roboflow: Used during development for AI model training only. Not used in production for live user data.
- Email/notification providers: For account communications.
- Stripe (future): Payment processing for Company subscriptions. Payment details are never stored on our servers — handled directly by Stripe.
- Recipients you choose when sharing a report.
7.5 Cookies (enodeus.ch website)
Our website (enodeus.ch) uses a single analytics cookie (Google Analytics 4) to help us understand how visitors use the site — for example, which pages are viewed most and where visitors come from. This cookie is only activated after you explicitly accept it via the cookie banner shown on your first visit. You can decline it, and the site will function normally without it.
We do not use marketing, advertising, or third-party tracking cookies. You can withdraw your consent at any time by clearing your browser's local storage for enodeus.ch and revisiting the site.
8. Data retention
We retain your data while your account is active. You may delete your account at any time within the app. When you delete your account:
- Your profile, authentication credentials, and user record are permanently deleted.
- You are removed from all company member lists.
- A backup copy is retained internally in
deletedUsers for anti-fraud and legal compliance purposes only. This is not accessible through the app.
- Asset trace logs (NDT audit records) may be retained as part of the company's industrial records even after your account deletion, as they form part of the immutable audit trail required by NDT standards. These records no longer contain personally identifiable information after account deletion.
9. Your rights
Subject to applicable law, you may access, correct, delete, restrict, or object to processing of your data, and request portability. Contact contact@enodeus.ch to exercise these rights. You also have the right to lodge a complaint with your local data-protection authority (Swiss FDPIC, or your EU member state authority).
10. Data security
We use HTTPS/TLS encryption in transit, Firebase security rules for access control (role-based: Inspector, Manager, Company), Firebase App Check to prevent unauthorized API access, and secure credential storage (iOS Keychain). No method of transmission or storage is completely secure.
11. International transfers
Your data may be processed on servers outside Switzerland or the EU (primarily the United States) through Google Firebase/Google Cloud. We rely on Standard Contractual Clauses (SCCs) and Google's Data Processing Terms as appropriate safeguards.
12. Subscription and billing
The Inspector (Freelancer) plan is free. The Company plan is USD 99/year with a 15-day free trial. Billing is processed by Stripe. We do not store payment card details. Subscription status may be stored in your user profile to control feature access.
13. Children
The service is intended for professional industrial inspectors and is not directed at individuals under 18.
14. Changes
We may update this policy. Material changes will be communicated through the app or by email. The current version is always available at enodeus.ch/privacy.html.