Questions about these Terms or the Service can be directed to: support@thermidoc.com
Thermidoc – Privacy Policy
Effective date: 02.09.2026
1. Who We Are
This Privacy Policy explains how Software Control AS, a company registered in Norway with organization number 916 454 724 ("Software Control", "we", "us"), processes personal data in connection with Thermidoc (previously marketed as iDOC), our reporting and documentation tool used in connection with inspections, available via web browser and the Thermidoc mobile applications (together, the "Service").
This Privacy Policy is a companion to, and should be read together with, Thermidoc's Terms of Use.
2. Scope
This Privacy Policy covers personal data processed through the Service (the Thermidoc application). Thermidoc's marketing website, thermidoc.com, is covered by its own, separate privacy notice.
3. Authorized Use
Software Control acts in two different capacities depending on the type of data:
- As data controller for account data about the individuals who use the Service on behalf of Customer (name, phone number, email address, optional profile picture) and for data about Customer as a business relationship (invoicing, order history, support communications).
- As data processor, acting on the instructions of Customer, for personal data that Customer itself registers in the Service about its own end customers, contacts, or inspection subjects (for example names, addresses, or contact details entered as part of an inspection report). Customer is the data controller for that data and is responsible for having a valid legal basis and providing appropriate notices to those individuals.
Software Control's processing as data processor is further governed by a separate Data Processing Agreement (DPA) entered into with Customer.
4. Categories of Personal Data We Collect
User account data: name, phone number, and email address, collected to create and manage access for each user Customer registers. Users may optionally add a profile picture.
Customer contact data: name, phone number, email address, and company details of Customer's contact person(s), used for account administration, invoicing, and support.
Data Customer registers about its own end customers or contacts: for example names, addresses, phone numbers, or email addresses entered in connection with an inspection or report, together with the inspection subject (property or object) they relate to.
Inspection content: images, thermal images, measurements, descriptions of findings, and related metadata, entered by Customer's users. This may incidentally include personal data if it appears within an image or description (for example, a visible name plate, or a person appearing in an image).
Technical and usage data: device type, app version, log data, and crash reports, collected automatically to operate, maintain, and secure the Service.
Customer's users must avoid photographing people, or capturing other sensitive personal data, as part of an inspection, unless directly necessary to document the relevant finding. Customer must not register personal data about individuals with a protected or confidential address, telephone number, or similar, and must not register or upload images that could violate or otherwise harm a person, including images linking to a person without consent, or images Customer does not have the rights to use. This is in addition to Customer's obligations regarding security-sensitive infrastructure described in the Terms of Use, Section 8.
5. Purposes and Legal Bases
We process personal data for the following purposes:
- To provide, operate, and maintain the Service, including creating and managing user access — necessary for the performance of the agreement with Customer.
- To invoice Customer and administer the customer relationship — necessary for the performance of the agreement, and to comply with legal obligations such as bookkeeping requirements.
- To provide support, including during the trial period — necessary for the performance of the agreement.
- To send information about the Service to registered users and contacts, including individuals previously registered under the Service's former name, iDOC — legitimate interest in maintaining our customer relationships. This information is about the Service itself and is not used for marketing outside of Thermidoc's own product and customer communications.
- To maintain the security of the Service and prevent misuse — legitimate interest.
- To improve and develop the Service using anonymized and aggregated data derived from inspection metadata and images relating to specific deviations or faults — legitimate interest, carried out only once data has been anonymized (see Section 6).
6. Aggregated and Anonymized Data
As described in the Terms of Use, Software Control may freely use, process, and commercialize anonymized and aggregated data derived from information entered into the Service, including by sharing such data with third parties. This is limited to metadata and images relating to the specific deviation or fault identified within an inspected area, and is carried out in anonymized form only — such data does not identify Customer, its personnel, or any individual.
In practice, this consists of statistics based on the number of registrations of a given type of fault or deviation, together with images extracted from inspections. Such images may be used, in anonymized form, to train AI models to recognize faults and defects. No personal data is shared as part of this.
As a baseline rule, Customer's users must not photograph people when registering an observation or finding (see Section 4). In addition, before any image is used for statistics or AI training, Software Control applies a two-step review: (i) an automated process screens out any image showing a person, so that it is excluded from the training data, and (ii) images that pass this filter are manually verified to confirm they are correctly associated with the relevant type of fault or deviation, which also serves as a manual check that no image showing a person or other sensitive content has been missed. In any event, an image of a finding is not linked, in Software Control's systems, to the identity of any individual — it is associated with the fault or deviation and the inspected object, not with a named person.
7. Who We Share Personal Data With
We share personal data with the following categories of recipients, as necessary to provide the Service:
- Amazon Web Services (AWS), for physical data storage and hosting, located in Germany (EU), and for user identity verification (see Section 10).
- Google, for image storage, located in the Netherlands (EU).
- Providers of invoicing, accounting, and payment services.
- Where applicable, a local subsidiary of Software Control AS or a local distribution partner in Customer's country, acting on our behalf or as a joint point of contact for Customer.
FLIR camera integration is limited to software and hardware compatibility. No inspection data, images, or other personal data is shared with FLIR or any FLIR platform (such as Ignite/ACE); all inspection data is stored solely on Software Control's own servers.
We do not sell or share identifiable personal data with third parties for their own marketing purposes. The anonymized and aggregated data described in Section 6 relates to registered findings and observations, and by its nature does not involve individuals unless a user has captured a person in an image — which is why the safeguards described in Section 6 are in place. Such data may be shared or commercialized as described in Section 6.
8. International Transfers
All infrastructure and sub-processors used by Software Control to deliver the Service are located within the EU/EEA. No transfers of personal data outside the EU/EEA currently take place.
9. Data Retention
Account and inspection data is retained for as long as Customer's account remains active. This data documents inspection findings and is not accounting material. As described in the Terms of Use, if an account has no active package and no purchase activity for 18 months, Software Control may notify Customer that continued storage requires purchase of a storage package, or that the data will otherwise be deleted after a further notice period.
10. Data Security
We work continuously to safeguard the security of the Service. Servers are located within Europe and run on redundant infrastructure to reduce the risk and duration of any unavailability.
Data in transit is encrypted. User identity verification uses AWS Cognito as part of the login mechanism.
Certain data may be stored locally on a user's device before it is synchronized to our servers, for example when the device is used offline. Users are responsible for the physical security of their own devices, as described in the Terms of Use, Section 14.
11. Security-Sensitive Locations
Where an inspection takes place at or in relation to security-sensitive infrastructure or other areas requiring a high level of security, Customer is responsible for maintaining its own routines to avoid capturing images or content that could reveal sensitive details, as described in the Terms of Use, Section 8. Software Control does not review or vet the content of images or reports beyond providing the technical infrastructure to store and transmit them.
12. Your Rights
If you are a Thermidoc user (see Section 4), you have the right to see what personal data we hold about you, request that inaccurate data be corrected, and request that we delete it. You may also object at any time to receiving product or service communications from us.
If personal data about you has instead been registered by one of our customers, for example as a business contact or in connection with an inspection, that customer is the data controller for that data (see Section 3), and such requests should be directed to the customer in the first instance. In particular, if you do not wish to be registered as a contact person or as an individual connected to an inspected object, you may ask that customer to have the relevant data deleted; Software Control will assist the customer in carrying out such deletion within 30 calendar days of receiving the request from the customer.
You also have the right to lodge a complaint with your local data protection authority (in Norway, Datatilsynet).
13. Business Contact Information
Contact information about business representatives (such as name, phone number, and email address of a contact person at Customer or at Customer's own end customer) is treated as personal data under this Privacy Policy, even where such information is also publicly available elsewhere (for example, in a business register). Being publicly available does not remove information from the scope of data protection law.
14. Children
The Service is offered exclusively to business customers and is not directed at, or intended for use by, children. We do not knowingly collect personal data from children.
15. Cookies and Similar Technologies
The Service (the Thermidoc application) does not use cookies or similar tracking technologies. Thermidoc's marketing website, thermidoc.com, is covered by its own, separate privacy and cookie notice.
16. Changes to This Policy
We may update this Privacy Policy from time to time. The then-current version will be published on Thermidoc's website, and material changes will also be notified through the application, consistent with the Terms of Use, Section 18.
17. Contact
Questions about this Privacy Policy, or requests relating to your personal data, can be directed to: support@thermidoc.com.
Data controller: Software Control AS, organization number 916 454 724, Norway.

