Privacy Notice
How we handle your account details and the data from the meters in your building.
Start with § 1 — we hold a different role for each, and everything else follows
from that.
§ 1 Two roles that have to be told apart
For your account details we are the controller. We decide about
your e-mail address, name, phone number, sign-ins and the messages we send, because
the application could not work without them. This part is identical across all
instances.
For consumption data we are the processor. Which meters are
installed in a building, how often they report, who has access to the data and how
long it is kept is decided by the owner or manager of the building. They are the
controller of that data; we process it on their instruction.
To exercise your rights over the consumption data of your flat, contact the manager
of your building. If you do not know who that is, write to us using § 12 and we will
point you to them — but we cannot make decisions about that data ourselves.
This matches how Article 4 GDPR defines a controller and a processor: the controller
is the one who determines the purposes and means of the processing.
§ 2 Who is the controller of account details
The controller of account details is ENEROOO s.r.o., company no. 22193855,
registered office at Záblatská 892/104, Heřmanice, 713 00 Ostrava, Czech Republic,
entered in the commercial register kept by the Regional Court in Ostrava under file
no. C 97599.
Contact e-mail: info@enerooo.com.
No data protection officer has been appointed. For data protection matters, use the
contact given in § 12.
§ 3 What data we process
Account details. E-mail address, name, phone number and its
verification, time zone, language, choice of units and formats, colour theme, date
of registration, last sign-in, who invited you and when, and — if an account is
suspended — the reason for it.
Assignment in the hierarchy. Which organisation, building or space
you belong to. For a resident this means a link between a person and a specific flat.
Consumption data. Readings from electricity, water, heat and gas
meters and from heat cost allocators, including the time of measurement. Electricity
meters store values at fifteen-minute intervals.
Operational records. System events, processing errors and records of
messages sent. They serve to run the system and to find out why data is missing.
Do you have to give us the data? To create an account we need an
e-mail address and a password; without them an account cannot exist. Name, phone
number and preferences are optional — although without a phone number we cannot send
you SMS alerts. Consumption data arises from measurement in the building; whether
measurement takes place is not decided by the user but by the manager of the building.
Consumption on its own is a technical figure, but at fifteen-minute resolution it
reveals when a flat is occupied — when somebody comes home or leaves on holiday. We
therefore treat it as data that says something about your private life, not as a mere
number.
§ 4 Purposes and legal bases
| Data |
Purpose |
Legal basis |
| Account details |
Creating and running the account, signing in, password recovery |
Performance of a contract |
| E-mail, phone number |
Operational messages and fault alerts |
Performance of a contract; consent for optional messages |
| Assignment in the hierarchy |
Restricting access to your scope |
Performance of a contract, legitimate interest in security |
| Consumption data |
Determined by the building manager — typically cost allocation and fault detection |
Set by the building manager; we process on their instruction |
| Operational records |
Security, fault finding, protection against misuse |
Legitimate interest in a working and secure service |
| reCAPTCHA data |
Preventing automated registrations |
Legitimate interest in protection against misuse |
Where we rely on legitimate interest, the interest is specifically:
-
for the assignment in the hierarchy — so that a user sees their own
flat and not the flats of others; without that restriction the system could not be
operated in a block of flats;
-
for operational records — so that we can find out why a reading is
missing or not displayed, and recognise an attempt to reach data outside the granted
scope;
-
for reCAPTCHA — so that the registration form is not used to create
accounts by machine.
§ 5 Who we pass data to
-
Google — reCAPTCHA on the registration form. Your IP address and
data about your browser behaviour are transmitted, even if you do not complete the
registration.
-
Twilio — sending e-mail through SendGrid, which Twilio operates,
and sending SMS. The e-mail address or phone number and the content of the message
are transmitted.
-
DigitalOcean — operation of the servers the instance runs on. The
server is located in the European Union; the provider is a US company.
-
Bugsnag — error tracking. If something fails in the application, a
technical description of the event is sent, including the identifier of the signed-in
user.
- The manager of your building — consumption data under § 1.
We do not pass data to third parties for advertising purposes and we do not sell it.
§ 6 Cookies and local storage
We use only the cookies without which the system would not work. We do not measure
traffic and we use no advertising or analytics tools — which is why we do not trouble
you with a consent banner, something strictly necessary cookies do not require.
-
__Secure-sessionid — keeps you signed in. It expires when you sign
out or after the period of inactivity set by the instance operator.
-
__Secure-csrftoken — protects submitted forms against misuse from
another site.
-
django_language — remembers the language you chose.
Appearance settings — light or dark theme, a collapsed sidebar, expanded menu groups
and an open filter in lists — are stored by your browser in local storage. That data
stays on your device and is not sent to the server.
Google reCAPTCHA runs on the registration form and stores cookies of its own; see § 5.
§ 7 Transfers outside the EU
Google, Twilio and Bugsnag may process data in the United States; DigitalOcean is a US
company as well, even though the server of your instance is located in the European
Union.
For Google and Twilio the transfer rests on their certification under the EU–US Data
Privacy Framework — an adequacy decision of the European Commission — and, in
addition, on standard contractual clauses. For Bugsnag, on standard contractual
clauses.
§ 8 How long we keep the data
The period differs according to the role in which we hold the data (§ 1). Where it
cannot be determined in advance, we state the criterion by which it is set.
-
Account details — for as long as the account exists. If you close
the account or your access ends, we remove the data once the reasons under the
points below no longer apply.
-
Consumption data — for as long as the manager of the building keeps
it in the system, because they are its controller (§ 1). The criterion is therefore
theirs, not ours; we process the data while the contract with the instance operator
lasts and then deal with it according to that contract. If a resident moves out,
their access to the flat ends; whether the measured values remain with the flat
without a link to a person is likewise decided by the manager of the building.
-
Operational records — for as long as they are needed to trace a
fault or investigate a security event.
-
Accounting and tax documents — 10 years, as required by the Czech
Accounting Act and the VAT Act.
§ 9 Your rights
You have the right of access to your data, to have it corrected or erased, to
restriction of processing, to data portability, and to object to processing based on
legitimate interest. Where processing rests on consent, you may withdraw it at any
time.
For account details, address your request to us (§ 12). For
consumption data, to the manager of your building — see § 1.
You also have the right to lodge a complaint with the Czech Data Protection Authority
(Úřad pro ochranu osobních údajů), Pplk. Sochora 27, Prague 7.
§ 10 Automated evaluation
The system evaluates readings automatically and raises alerts — for example when a
limit is exceeded or when a meter has stopped reporting. Those alerts concern
devices, not the assessment of people, and have no legal consequences
for you.
We carry out no automated decision-making within the meaning of Article 22 GDPR and no
profiling of individuals.
§ 11 Security
Access is limited to the scope assigned to a user; database queries are filtered
centrally so that the data of one organisation cannot be shown to another. Passwords
are stored as irreversible hashes. Communication is encrypted.
Signing in as a user. In justified cases, support staff can sign in
under a user’s identity in order to trace a fault. For the duration of such access a
notice is permanently displayed in the application and the access is logged.
§ 12 Contact and effect
For data protection matters, contact us at
info@enerooo.com.
This notice takes effect on the day it is published in the application. Changes will
be published in the same place; we will notify you of any substantial change.
The terms governing use of the software are a separate document:
Terms of Service.