Privacy
Privacy policy
Which data stays on the device, which is processed, and which rights you can exercise at any time.
This policy explains how personal data is processed when using the TurboFix program and the turbofix.it website, pursuant to EU Regulation 2016/679 (“GDPR”).
1. Data controller
The data controller is Eric Gilberti. For any request concerning their data, the data subject can write to supporto@turbofix.it. Any further identifying details of the controller are provided on request.
2. The principle applied: the computer's data stays on the device
The measurements taken on the computer (space, memory, startup, temperatures, disk health, processes, Windows errors) are read and processed only on the user's device. The history of the PC, the record of conversations with the assistant, the diagnostic logs and the saved reports are files on that disk. We don't receive them and we can't read them.
The assistant works on the user's computer and uses no artificial intelligence model: it is a rules engine, built into the program. There is nothing to download separately and nothing to train. Questions and PC data are not sent to anyone, not even to us.
There is no account to create and no subscription. An email address is needed to receive the license key (point a) and an internet connection to activate it (point f). After activation the program re-checks the license status when the network is available, but this is not a condition for using it.
3. The data we process (only this)
a) The email address
What: the email address provided to receive the license key. Alongside it we keep the assigned key, the date and the outcome of sending the message. Why: the key is delivered only by email, so it's needed to send it, to send it again if lost, and to avoid issuing two keys to the same person. Legal basis: performance of the service requested by the data subject (Art. 6(1)(b) GDPR); where required, the data subject's consent (Art. 6(1)(a)). The email address is not passed on to third parties and is not used for advertising: there is no newsletter and we don't write for any other reason. The data subject can request its deletion at any time.
b) Anonymous usage statistics: optional, off by default
What: which screens are opened, which operations are launched and their outcome, the type of question asked of the assistant, as a category (for example “why is it slow”), and the situations the assistant recognizes, again as a label (for example “disk almost full”). Never the text typed, never a file name, never the computer or user name: only labels taken from closed lists go out, and anything with no match in those lists isn't even recorded on that computer. On our server these events are filed under an identifier that changes every month and cannot be traced to the user; the IP address is not stored.
Legal basis: the data subject's consent (Art. 6(1)(a) GDPR). They are off by default: the request appears once, at first launch, and they are turned on only by choosing to via the “Anonymous usage statistics” switch in Settings; the data subject can withdraw consent at any time from the same place. When they are turned off, the queue of data not yet sent is deleted from the computer.
c) Count of active installations
It falls under the same switch as point b, so the same consent and the same “off by default” apply. It works differently, though, and we'd rather say so than hide it.
What: a lightweight “heartbeat” with a random identifier generated by the program (not derived from the hardware, not linked to the name, the email address or the license key) and the app version. It serves only to know how many installations are still in use and on which version, to decide when to stop updating an old version. It's sent at startup and once a day.
Note, this is where the difference lies: unlike the events in point b, this identifier does not change every month. It stays the same, and on our server there is one row per installation with the date of first contact, the date of the last one and the version. It contains nothing about the user and we don't link it to anyone, but it is a persistent identifier, and we declare it as such.
d) Error reports: on by default, can be turned off
What: if the program fails, the technical details of the failure (type of error, point in the program, version in use) together with the same identifier as in point c. Before sending, the report is scrubbed on the computer: the Windows username, the computer name and the paths of personal folders are replaced with placeholders. It contains neither file contents nor passwords. Why: to fix defects in the program, which show up on real computers and not on ours. Legal basis: legitimate interest in identifying and fixing malfunctions (Art. 6(1)(f) GDPR). They are on by default and are the way problems get found and fixed for everyone: the data subject can turn them off at any time from Settings, and can object to the processing by writing to us. Kept for as long as needed to fix the problem and in any case no longer than 12 months.
e) PC operating data
Disk space, startup programs, temperatures, disk health, processes, installed programs, devices and all the other measurements: they stay on that computer, in the local history. They are not sent.
f) License activation and verification
What: on activation, the program sends our server the key, the app version and a fingerprint of the computer. The fingerprint is a 32-character sequence computed with a non-reversible cryptographic function from a technical identifier that Windows generates on its own: it neither contains nor allows anyone to derive the computer name, the username or any other data about the user, and cannot be used by other programs to recognize the same computer.
Why: to issue the license and tie it to the computer it was activated on, to count the computers in use (at most three per key) and to verify that the license is still valid. When: on activation, and then at every program launch, but no more than once every six hours, for verification only. Legal basis: performance of the license agreement (Art. 6(1)(b) GDPR) and legitimate interest in protecting the software from unauthorized use (Art. 6(1)(f)).
g) Reviews
What: when a review is left from the program, the rating from 1 to 5, the text (optional) and the chosen signature (optional) are sent, together with the identifier from point c, the app version and a non-reversible fingerprint of the IP address, which we use only to prevent abuse. The text is written by whoever submits it: better not to include personal data, because the review, if approved, is published on turbofix.it under the chosen signature. Legal basis: the data subject's consent, expressed by submitting the review (Art. 6(1)(a) GDPR). The data subject can request its removal at any time. Submitting a review is a voluntary, separate action: it happens even if the statistics in point b are turned off.
h) Update checks, downloads and website visits
To find out whether a newer version exists, the app connects to the website and reads a small public file: in that request we send no identifier. For these requests, as for any visit to a website, the hosting server may record standard technical data in its logs (for example IP address, date and time, browser or client type), used for the security and operation of the service. Legal basis: legitimate interest in security and proper operation (Art. 6(1)(f) GDPR).
The website's “Suggest a change” form sends nothing to our server: it prepares a message and opens the default email program, and sending it remains the user's choice.
4. No selling, no advertising, no profiling
No data is sold or passed on to third parties. There is no advertising and no ad tracking on the website or in the app. We do no profiling and make no automated decisions concerning the user.
5. Who they are disclosed to
The few pieces of data that leave the computer are stored on the server hosting turbofix.it, run by our hosting provider, and the email with the key travels through the outgoing mail service we use to send it. They are the only parties that process data on our behalf, as data processors. No other recipients, no analytics service, no advertising network.
6. How long we keep them
- Email address and license data (key, fingerprints of activated computers): for as long as we manage the license; deleted on request.
- Anonymous statistics: only while consent is active; in any case they are aggregate counters that cannot be traced to you.
- Installation count: while consent is active. If the program stops checking in, the row stays as it is and the installation drops out of the active count.
- Error reports: as long as needed to fix the defect, no longer than 12 months.
- Reviews: while they remain published, or until removal is requested.
- Technical server logs: for the period set by the hosting provider for security and diagnostics.
7. The data subject's rights
The data subject can exercise at any time the rights set out in Articles 15 to 22 GDPR: access to their data, rectification, erasure, restriction of processing, objection, portability, and withdrawal of consent at any time (withdrawal does not affect processing already carried out). To exercise them, just write to supporto@turbofix.it.
The data subject also has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) or with the supervisory authority of their country of residence.
8. Transfers outside the European Union
None take place. The computer's data is processed locally, on the user's device, and the few pieces of data that go out stay on the server hosting the website.
9. Security
We adopt reasonable technical and organizational measures to protect the few pieces of data processed, taking into account their nature and the fact that most information never leaves the computer. Among them: license data is stored outside the website's public folder, the server endpoints are rate-limited against abuse, and program updates are signed and verified before they install.
10. Cookies
The website uses no profiling cookies and no third-party tracking tools. The details are in the Cookie policy.
11. Changes to this policy
This policy may be updated. The version published on this page, with the last-updated date shown at the top, is the one that applies.