Skip to content

Privacy Policy

Privacy Policy

Effective as of August 8, 2026 — how Veni Solutions processes personal data on the veni.care website and within the local-first VeniCare in-home platform.

1. Executive Summary & Our Privacy Guarantee

At Veni Solutions (“VeniCare,” “we,” “us,” or “our”), privacy is not a marketing checkbox—it is the foundational architecture of our hardware and software solutions.

Unlike traditional eldercare and remote monitoring systems that transmit private bodily vitals, daily routines, and audio/visual feeds to third-party cloud servers, VeniCare operates on a “Local-First, Privacy-by-Design” mandate.

The VeniCare Privacy Promise

  • Your Data Stays Home: All ambient, health, hydration, medication, and behavioral data are processed and stored locally on your in-home VeniHub.
  • Zero Cloud Dependency: Core system logic—including fall detection, voice interaction, and hydration tracking—runs entirely offline on local edge hardware.
  • No Invasive Surveillance: We do not use optical cameras or video feeds. Sensors utilize privacy-preserving millimeter-wave Radar, localized volume/mass measurement, and offline voice modules.
  • No Overseas Data Leaks: We do not sell, rent, monetimize, or export personal or health data to cloud databases, overseas servers, or third-party advertisers.

2. Controller Information & Contact Details

Under the EU General Data Protection Regulation (GDPR / DSGVO), the Data Controller responsible for processing data associated with the website veni.care and Veni Solutions services is:

  • Veni Solutions
  • Urbanstraße 84
  • 10967 Berlin
  • Federal Republic of Germany

For any questions regarding data protection, exercising your rights, or auditing local hub configurations, you can contact us at info@veni.net.

3. Data Processing Architecture: Website vs. In-Home VeniCare System

It is critical to distinguish between data interactions on our public website (veni.care) and data processing within the in-home VeniCare Hardware & Software Platform.

┌─────────────────────────────────────────────────────────────────┐
│                   VeniCare Privacy Boundary                     │
├────────────────────────────────┬────────────────────────────────┤
│    Public Website (veni.care)  │   In-Home Platform (VeniHub)   │
├────────────────────────────────┼────────────────────────────────┤
│ • Minimal web log collection   │ • 100% Local Processing        │
│ • Contact form inquiries       │ • Edge Health Data Storage     │
│ • No invasive cloud tracking   │ • Direct Encrypted Tunneling   │
└────────────────────────────────┴────────────────────────────────┘

4. Processing on the Public Website (veni.care)

When you visit our promotional or informational website (https://veni.care), we process only minimal technical data necessary to deliver the site securely and respond to direct business inquiries.

4.1 Server Log Files

When accessing veni.care, your web browser automatically transmits server log data required for technical connectivity and security.

  • Categories of Data: Anonymized IP address, date and time of request, time zone offset, specific page/file requested, HTTP status code, data volume transferred, referrer URL, and browser/operating system type.
  • Purpose: Ensuring site stability, security against DDoS attacks, and system diagnostics.
  • Legal Basis: Art. 6(1)(f) GDPR (Legitimate interest in maintaining a secure and functional web presence).
  • Retention: Log files are automatically deleted or irreversibly anonymized after 7 days.

4.2 Direct Contact & Inquiries (Email & Phone)

When you communicate with us via email (info@veni.net, sales@veni.net) or phone (+49 163 261 7814):

  • Categories of Data: Name, contact details (email address, phone number), organization, and the content of your message.
  • Purpose: Addressing your sales inquiries, customer support requests, or partnership evaluations.
  • Legal Basis: Art. 6(1)(b) GDPR (Pre-contractual measures or contract performance) or Art. 6(1)(f) GDPR (Legitimate interest in communicating with prospective clients).
  • Retention: Inquiries are deleted once the matter is resolved, unless commercial or tax retention obligations apply (Art. 6(1)(c) GDPR).

4.3 Cookies & Web Tracking

  • No Invasive Tracking: veni.care does not employ third-party cross-site trackers, advertising cookies, or behavioral profiling pixels (such as Google Analytics or Meta Pixels).
  • Essential Cookies Only: If session cookies are required for site navigation, they are strictly necessary and non-intrusive.

5. In-Home VeniCare Platform & IoT Ecosystem

This section governs the processing of data collected by VeniCare hardware modules installed in a residence.

5.1 Local Data Boundary (VeniHub)

The central component of the system—the VeniHub—is an edge-computing server situated physically inside the senior’s living space.

  1. Local Storage: All telemetry, motion patterns, hydration logs, medication interaction timestamps, and system configurations are stored locally on the VeniHub’s encrypted storage.
  2. Local AI & Rule Processing: Algorithms for fall detection, anomaly recognition (e.g., prolonged room absence), and hydration analysis run on the VeniHub hardware.
  3. No Default Cloud Mirroring: Veni Solutions does not host a centralized database of senior health metrics or activity logs.

5.2 Specific Sub-System Modules & Data Practices

Hardware ModuleData CollectedProcessing MechanismCamera / Cloud Policy
Radar Fall SensorMillimeter-wave Doppler radar reflections, movement velocity, spatial posture coordinates.Processed locally in real time on the sensor & VeniHub to detect falls.NO Cameras. No optical images are ever captured or stored.
HydroBuddyLiquid volume levels, container tilt/movement, timestamped intake metrics.Syncs locally with VeniHub via local mesh network. Displayed on local e-paper UI.Local processing. Zero cloud logging.
Medication ModuleCompartment opening timestamps, adherence confirmations.Logged locally to generate scheduled alerts via local speaker or screen.Stored exclusively on VeniHub.
Offline Voice AssistantAudio wake-word activation (e.g., “BOB” / “ANA”), speech recognition commands.100% Offline Processing. Audio is processed locally on-device. Audio streams are discarded after command execution.NO Cloud Audio Streaming. Zero transmission to external voice servers.
Energy & Ambient SensorsAppliance power usage, environmental activity signals.Analyzed locally on VeniHub to infer routine status (e.g., stove left on).Stored exclusively on VeniHub.

6. Remote Caregiver Access & Encryption Architecture

Family members or authorized caregivers may connect to the VeniHub via the VeniCare Mobile Application to receive alerts or view activity dashboards.

6.1 Direct Peer-to-Peer Tunneling

  • Direct Encrypted Link: Remote access occurs via an encrypted peer-to-peer (P2P) tunnel or secure end-to-end cryptographic connection directly between the caregiver’s device and the in-home VeniHub.
  • Zero-Knowledge Relay: In cases where network configurations require a relay server to traverse NAT/firewalls, Veni Solutions operates a zero-knowledge relay in Germany. Payload data remains end-to-end encrypted; Veni Solutions cannot read, decrypt, or store the underlying health metrics.

6.2 Data Categories & Consent for Caregiver Access

  • Health Data (Art. 9 GDPR): Data such as hydration percentages, fall history, and medication logs constitute special categories of health data under Art. 9(1) GDPR.
  • Explicit Consent: Remote caregiver sharing is disabled by default. It requires explicit activation and consent from the resident (or their legally authorized guardian) pursuant to Art. 9(2)(a) GDPR.
  • Access Control: The resident retains full authority to grant, scope, or revoke remote caregiver permissions at any time via the local VeniHub control interface.

7. Legal Bases for Processing Under GDPR

We process personal and health data strictly in accordance with European data protection law:

  1. Art. 6(1)(b) GDPR (Contractual Performance): Necessary for fulfilling hardware operation and local service agreements.
  2. Art. 9(2)(a) GDPR (Explicit Consent): Explicit consent for local health metric analysis (fall alerts, hydration tracking) and optional caregiver sharing.
  3. Art. 6(1)(f) GDPR (Legitimate Interest): Securing the website veni.care and protecting against cyber threats.
  4. Art. 6(1)(c) GDPR (Legal Obligation): Compliance with statutory tax, commercial, or legal record-keeping obligations in Germany.

8. Third-Party Disclosures & International Transfers

8.1 No Third-Party Data Sales

Veni Solutions does not sell, license, lease, or monetize personal data, health telemetry, or usage metrics under any circumstances.

8.2 Subprocessors

Because our system architecture is local-first, we do not utilize external cloud data processors for core system operations. Any website hosting infrastructure utilized for veni.care resides within certified, GDPR-compliant data centers in Germany or the European Union.

8.3 International Data Transfers (Third Countries)

Core platform operations involve zero data transfers to countries outside the European Economic Area (EEA). All localized engineering, support, and web hosting comply with German and EU sovereignty standards.

9. Data Retention & Local Deletion Controls

  • In-Home Log Rotation: Sensor logs and activity trends stored on the local VeniHub are subject to automatic local rotation and purge policies configurable by the user.
  • User-Initiated Deletion: Residents or authorized administrators can initiate a total hardware factory reset directly on the physical VeniHub, permanently wiping all stored logs, calibration data, and encryption keys.
  • Website Communication Data: Inquiries sent to info@veni.net are retained only as long as necessary to fulfill the request, or as mandated by German commercial retention laws (up to 6 to 10 years for statutory business correspondence).

10. Data Security Measures (Art. 32 GDPR)

Veni Solutions enforces rigorous technical and organizational security measures (TOMs) across hardware and software layers:

  • Hardware Isolation: The VeniHub functions as an air-gapped or network-isolated private server, protecting the IoT sensor mesh from external internet vulnerabilities.
  • End-to-End Cryptography: Communication between sensors, VeniHub, and local interfaces uses state-of-the-art encrypted protocols.
  • Physical & Logical Access Boundaries: No backdoors, remote master keys, or administrative cloud access exist to bypass local user authentication.
  • No Cameras / Microphones Offline: Elimination of camera hardware prevents visual intercept risks; offline microphone processing prevents continuous listening leakages.

11. Rights of the Data Subject

Under Arts. 15–22 of the GDPR, you possess the following rights regarding your personal data:

  1. Right of Access (Art. 15 GDPR): Right to obtain confirmation as to whether your personal data is processed and request copies of processed data. (For local VeniHub data, full access is granted directly via the local user interface).
  2. Right to Rectification (Art. 16 GDPR): Right to correct inaccurate or incomplete personal records.
  3. Right to Erasure / “Right to be Forgotten” (Art. 17 GDPR): Right to request the deletion of your personal data stored by us or wiped from your VeniHub.
  4. Right to Restriction of Processing (Art. 18 GDPR): Right to restrict data processing under specific statutory conditions.
  5. Right to Data Portability (Art. 20 GDPR): Right to receive your personal data in a structured, commonly used, and machine-readable format.
  6. Right to Object (Art. 21 GDPR): Right to object at any time to processing based on legitimate interests (Art. 6(1)(f) GDPR).
  7. Right to Withdraw Consent (Art. 7(3) GDPR): Right to revoke any given consent at any time with future effect.

To exercise any of these rights, please contact our Data Protection Team at info@veni.net or send a physical request to our Berlin address listed in Section 2.

Right to Lodge a Complaint

You also have the right to lodge a complaint with a competent data protection supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

The competent supervisory authority for our headquarters in Berlin, Germany is:

  • Berliner Beauftragte für Datenschutz und Informationsfreiheit
  • Alt-Moabit 140
  • 10557 Berlin, Germany

12. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect technological enhancements, new hardware modules, or regulatory changes. Any updates will be published on https://veni.care/privacy with an updated “Effective Date.”

13. Contact & Inquiries

For further information regarding VeniCare’s privacy-first architecture, local data handling, or technical documentation, please contact:

  • Veni Solutions
  • Urbanstraße 84, 10967 Berlin, Germany