Privacy Policy HEMS

(As of 09/2022)
 

We process your personal data in accordance with the current regulations of the Federal Republic of Germany and the European Union (EU). The protection of your personal information is our top priority. Below you will find information about what data we process, in what form, on what legal basis, for what purpose, for how long, to what extent you have a right of objection, and how you can exercise this right. If your consent is required, this will be indicated at the appropriate place and you will have the option of giving or withholding your consent. Of course, even after giving your consent, you have the right to revoke it at any time.

1. Responsible party [1]

Responsible in terms of data protection regulations is:

Consolinno Energy GmbH
represented by the managing director
Franz-Mayer-Straße 1
93053 Regensburg

The responsible company data protection officer (CPO) is:

Niklas Hanitsch
Datenschutz hoch 4 GmbH
Franz-Mayer-Str. 1
93053 Regensburg, Germany

We would like to take this opportunity to inform you of your right to lodge a complaint with the supervisory authority in accordance with Art. 77 GDPR. Accordingly, without prejudice to any other legal remedy, every data subject has the right to lodge a complaint with the supervisory authority if they believe that the processing of personal data concerning them violates the General Data Protection Regulation.

The contact details of the supervisory authority responsible for the controller are as follows:

Bavarian State Office for Data Protection Supervision
Promenade 18
91522 Ansbach

2. Information about your rights as a data subject

2.1 If the legal requirements are met, you have the following rights with regard to your personal data, unless there is a legal exception:

  • Right to information (Art. 15 GDPR): You have the right to request information from the controller as to whether personal data concerning you is being processed. If this is the case, you have the right to obtain information about this personal data and further information related to it.
  • Right to rectification (Art. 16 GDPR): You have the right to request that the controller rectify inaccurate personal data concerning you without undue delay. Taking into account the purposes of the processing, you have the right to request that incomplete personal data be completed, including by means of a supplementary statement.
  • Right to erasure (Art. 17 GDPR): You have the right to request that the controller erase personal data concerning you without undue delay, and the controller is obliged to erase personal data without undue delay if one of the reasons specified in Art. 17 (1) GDPR applies and no exceptions apply.
  • Right to restriction of processing (Art. 18 GDPR): You have the right to request that the controller restrict the processing (formerly: blocking) of your personal data if one of the conditions of Art. 18 (1) GDPR is met and no exceptions apply.
  • Right to data portability (Art. 20 GDPR): You have the right to receive the personal data concerning you that you have provided to a controller in a structured, commonly used, and machine-readable format, and you have the right to transmit this data to another controller without hindrance from the controller to whom the personal data has been provided, provided that the further requirements of Art. 20 (1) GDPR are met and no exceptions apply.
  • Right to object to processing (Art. 21 GDPR): You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(e) (public interest or exercise of official authority) or (f) (protection of legitimate interests) GDPR.

2.2 If you would like further information about your personal data or have any further questions about the processing of your personal data provided to us, or if you would like to have your data corrected or deleted, please contact us at the address given in section 3, "Exercising your right to object and withdraw consent."

3. Exercising the right of objection and withdrawal

You may have the right to object to the processing of your data (see section 2.1, last bullet point). You also have the right to revoke any consent you have given us with future effect. In this case, we will immediately cease processing your data for this purpose. You can send us your objection or revocation at any time by post, fax, or email.

By mail:
Consolinno Energy GmbH
Franz-Mayer-Straße 1
93053 Regensburg, Germany

By email:
info@consolinno.de

4. Use of hardware and mobile application (app)

4.1 Type and scope of data processing:

When using our hardware and accessing our app, it is technically necessary to process various data, in particular to enable use and error-free communication between your device and our cloud. The following data is automatically collected and logged in a log file:

  • Date and time of access
  • Hardware type and version (including serial number)
  • Operating system type and version
  • IP addresses of the devices
  • The IP address of your connection
  • access provider
  • Data on connected mobile devices (manufacturer, type)
  • Data from devices integrated into the smart home system (operating states, operating hours, energy consumption, system status, system settings, system location, error codes, measured values such as temperatures)

We collect this data in a non-personal form as a matter of principle. In exceptional cases, it is not possible to avoid linking the data to a natural person. For additional data processing in the context of the beta test, please refer to section 6 below.

4.2 Purpose:

This is done to enable the use of the hardware and software in the first place, in particular for the purposes of internal technical processing (connection establishment), system security, technical administration of the system and network infrastructure, and to optimize our offering and product. We reserve the right to check the log file retrospectively if there are concrete indications that there is justified suspicion of illegal use.

4.3 Legal basis:

The temporary processing of the data and the log file is carried out on the basis of legitimate interest for the above-mentioned purpose in accordance with Art. 6 (1) sentence 1 lit. f) GDPR and for the fulfillment of the contract with you in accordance with Art. 6 (1) sentence 1 lit. b) GDPR.

4.4 Recipients of the data:

The anonymized data is necessarily forwarded to our hosting provider, who manages our web server physically and technically:

Hosting provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany

4.5 Storage period and deletion:

The IP address is only stored by us in the case of remote access. Data storage is based on legal regulations.

4.6 Objection or revocation:

This data processing is essential for the operation of our hardware and software. Therefore, any objection is subject to a corresponding weighing of interests.

 

5. Registration

5.1 Type and scope of data processing:

You have the option of registering in our app. This requires your consent. In order to successfully complete this registration process, we need the following information from you:

  • email address
  • password

During registration, your IP address, date, and time are also stored. Personal data is not evaluated, except in the case of participation in the beta test (see section 6). However, we reserve the right to subsequently check the stored data if there are concrete indications that there is reasonable suspicion of fraudulent registration.

5.2 Purpose:

Registration allows you to use certain services or perform actions that would not be possible without registration. This is done for the following purposes:

  • Operation of hardware and software
  • Using the app
  • Use of the cloud

Your data is stored in our system to enable you to use our services without having to re-enter your data each time. We use your email address to send you confirmation emails for changes you have made to your profile data or to reset your password, as well as to inform you about necessary software updates. We will only send you other emails if you wish us to do so and have given us your consent for this purpose. Your IP address is stored along with the date and time to prevent misuse.

5.3 Legal basis:

The data is processed on the basis of your consent in accordance with Art. 6 (1) sentence 1 lit. a) GDPR.

5.4 Storage period and deletion:

The data will generally be stored until you cancel your registration and there are no longer any legal retention periods.

5.5 Objection or revocation:

You have the right to cancel your registration at any time, change your stored data, and revoke your consent with future effect. You can change your password yourself at any time. Upon cancellation and/or revocation, access to the hardware and software will no longer be possible.

6. Consent granted

Where necessary, you may have given us your consent to process your personal data. In this case, we have logged your consent in each instance. We are legally obliged to keep the text of the respective consent available for you at all times. You can, of course, revoke any consent you have given us at any time with effect for the future. You can find out how to exercise your right of revocation under section 3, "Exercising your right of objection and revocation."

Consent for the registration of a user account:

☐ Yes,

I would like to open a user account so that I can log in to the app. For this purpose, I consent to my data (email address and password) being stored in the database. I can revoke this consent at any time with future effect by contacting the address at https://hems.consolinno.de/datenschutz/ and requesting the deletion of my user account. To log this process, my IP address and the date and time of registration will be stored in a database and will only be deleted when I revoke my consent, unless further storage is required by law. I have read and understood the terms and conditions at https://hems.consolinno.de/agb/.

7. Electronic mail (email) / Contacting us

7.1 Unencrypted information

Information that you send to us unencrypted via electronic mail (email) may be read by third parties during transmission. As a rule, we cannot verify your identity and do not know who the real owner of an email address is. Legally secure communication via simple email is therefore not guaranteed. Like many providers, we use filters against unwanted advertising ("spam filters"), which in some cases also automatically classify normal emails as unwanted advertising and delete them. Emails containing harmful programs ("viruses") are automatically deleted by us in all cases. If you wish to send us messages that require protection, we recommend that you send the message to us by conventional mail.

7.2 Type and scope of data processing

If you contact us, your data, IP address, and the date and time will be stored.

7.3 Purpose

This is done primarily for communication purposes and to protect our systems against misuse.

7.4 Legal basis

The data is processed on the basis of legitimate interest for the above-mentioned purpose in accordance with Art. 6 (1) sentence 1 lit. f) GDPR.

7.5 Storage period and deletion

The data will only be deleted if there are no contractual or legal obligations preventing deletion.

7.6 Objection or revocation

You can object to being contacted by email at any time. In this case, no further correspondence via email can take place.

8. Validity

We constantly strive to further develop our hardware and software and to use new technologies. It may therefore be necessary to amend or adapt this privacy policy. We therefore reserve the right to amend this policy at any time with future effect. Please visit this page regularly and reread the current privacy policy from time to time.

[1] For reasons of better readability, the simultaneous use of masculine, feminine, and diverse language forms (m/f/d) is avoided. All references to persons apply equally to all genders.