Privacy policy
Last updated: September 30, 2026
Data controller: TECHEMV SRL, Pordenone, Italy — VAT IT01960380937 — info@techemv.it. This policy is written for the GDPR in plain language.
Quotes, orders and invoicing
We process name, company, e-mail, billing details and VAT ID to prepare quotes, deliver licenses and meet invoicing and tax obligations (legal bases: contract and legal obligation). Invoicing records are kept for 10 years as required by Italian tax law. For online checkout orders, payment is processed by FastSpring as Merchant of Record under its own privacy policy; TECHEMV receives the order details needed for fulfilment (name, company, e-mail, VAT ID, order id) and never sees full payment card data.
To know which channels bring customers, an online order carries
a tag with where the visit came from and the page it was placed
on: the utm_source and utm_medium of the
link that opened this website (the Software’s own links use
utm_source=app and name the menu or dialog that was
used), otherwise the host name of the referring site, otherwise
“direct”. The same source is added as a
“Source” line to a quote e-mail started from this
website. The source is kept in the browser tab only for the visit
(session storage) and names no person (legal basis: legitimate
interest in measuring sales channels).
License activation
When an activation code is used, the Software sends the code, a hardware identifier (a non-reversible machine fingerprint), a random installation identifier, app version, app language, OS and architecture; the server also logs the request IP and derives a coarse location (country/city). Purpose: issuing the signed license, enforcing the number of purchased seats and preventing abuse (legal basis: contract). After activation the license is verified locally: the Software does not need to contact our servers again to keep working.
One exception: a license activated online repeats the activation request above in the background at start-up, with the stored code and the same data — once a week, and at most once a day from 14 days before it expires (and after it has expired). This picks up a renewal without asking you to do anything and, if the activation code has been revoked (for example after a refund), returns the Software to the Community tier. If our server cannot be reached nothing changes and no error is shown. Offline license keys never trigger it.
Usage statistics (opt-in, default OFF)
If — and only if — you enable “Send usage
statistics” in Settings → Privacy, the Software
sends, at most once a day: the product name, app version, OS and
processor architecture, app language, license tier, days since
installation, number of active plugin packs, usage counters (e.g.
messages parsed, validations run), a timestamp, the random
installation identifier and — for licenses activated online
— the activation code (used to flag revoked licenses).
Never sent: message content, patient data, file
names, host names, user names. The exact payload can be previewed
in the app before enabling. Telemetry records are deleted
automatically after 90 days. Legal basis: consent, withdrawable at
any time with the same toggle. On managed machines an administrator
can force it off for every user (environment variable
BRIDGELAB_DISABLE_TELEMETRY=1, or
"disable_telemetry": true in the machine
policy.json); nothing is sent then.
Update check
Once a day, shortly after start-up, the Software asks GitHub
(api.github.com) for the number of the latest
BridgeLab release, so it can tell you when a new version is
out. The request carries no identifier, no license data and
nothing about your files; like any web request it reaches
GitHub from your IP address, and GitHub’s own privacy
statement applies to it. TECHEMV receives nothing. Nothing
is requested until you decide: the Windows installer asks during
setup, and otherwise BridgeLab asks the first time it starts.
You can change your answer in Settings → Privacy
(“Check for new versions at startup”); without
internet access the check is skipped silently.
Administrators can turn it off for every user of a machine with
the BRIDGELAB_DISABLE_UPDATE_CHECK=1 environment
variable or a policy.json file (see the user
manual). Help → Check for Updates makes the same
request on demand.
Support
E-mails you send us are kept as long as needed to help you.
Where data lives
License and telemetry data are processed on AWS in the EU (Milan
region, eu-south-1). This website is served by GitHub Pages, which
may log IP addresses for security; the site itself sets no cookies.
This website uses Cloudflare Web Analytics, a cookieless,
privacy-first analytics service that does not fingerprint or track
individual visitors. Each view of the home page also asks GitHub
(api.github.com) for the number of the latest release,
to show it; the request reaches GitHub from your IP address and
carries nothing else. When online checkout is available, the home
page loads FastSpring’s checkout script
(sbl.onfastspring.com) on every view, not only when you
buy, so FastSpring receives your IP address and may set its own
functional cookies.
Your rights
Access, rectification, erasure, restriction, portability, objection, and complaint to the Garante per la protezione dei dati personali. Write to info@techemv.it. We do not sell personal data and do not use it for advertising.
Patient data in your messages
HL7/FHIR content you open in BridgeLab stays on your machine; TECHEMV has no access to it. You remain the controller of any personal data contained in your messages.
BridgeLab keeps some of it in its local database: the open tabs
of the session (when session restore is on), the communication
history, and your test cases. The history keeps the full request
and response of the latest 100 exchanges, up to 256 KB each,
including the messages the MLLP listener receives and the ACKs it
returns, so it holds the patient data those messages carry. On
Windows that database is in %APPDATA%\BridgeLab, the
roaming part of the profile: where roaming profiles or folder
redirection are in use it is copied to the server with the rest of
the profile. Turn off session restore, clear the history and keep
test cases anonymized if that matters for you.