Personal data is information that relates to an identified or identifiable person. This includes, above all, information that makes it possible to draw conclusions about your identity such as your name, telephone number, and address or e-mail address. Statistical data that we collect, for example, when you visit our website and that cannot be associated with your person, is not covered by the term “personal data”.
Your contact person and so-called person responsible for the processing of your personal data when visiting this website within the meaning of the EU General Data Protection Regulation (GDPR) is
ubitricity Gesellschaft für verteilte Energiesysteme mbH
Phone +49 (0)30 – 398 371 690
Fax: +49 (0)30 – 398 371 699
For any questions about privacy in connection with our products or the use of our website, you can always contact our data protection officer. This can be reached at the above postal address as well as at the previously stated e-mail address (keyword: “for the attention of the data protection officer”).
2. Data processing on our website
2.1 Visiting our website / access data
When you use our website, we collect the access data that your browser automatically transmits to enable you to visit the website. The access data include in particular:
The data processing of this access data is necessary to enable the visit of the website and to ensure the long-term functionality and security of our systems. The access data is also temporarily stored in internal log files for the purposes described above to provide statistical information on the use of our website in order to further develop our website in terms of the usage habits of our visitors (for example, when the share of mobile devices accessing our website increases) and to maintain and administer our website in general. The legal basis is Art. 6 para. 1 sentence 1 lit. b GDPR.
The information stored in the log files does not allow any direct inference to your person – in particular, we store the IP addresses only in a shortened, anonymized form. The log files are stored for 30 days and archived after subsequent anonymization.
2.2. Contacting us
The collection of information marked on the online contact form is required to process your request. These are your name and your e-mail address. With regard to other data fields, you decide yourself whether and which of these information you want to make available to us.
With regard to communicating with you via the e-mail address provided by you via our online contact form, we use the so-called “double opt-in procedure”. This means we will only process your request and send you further e-mails if you confirm in our notification e-mail that you have initiated the request and that you are the owner of the specified e-mail address by clicking on a link. On confirmation we will save your e-mail address, the time of confirmation and the IP address used for confirmation until your request has been completely processed, unless we still need your request to fulfill contractual or legal obligations (see section “Duration of storage”). The sole purpose of the storage is to send you the newsletter and to prove your registration. If your e-mail address is not confirmed within 24 hours, we delete the data you entered.
The described processing of your data is carried out exclusively in so far and to the extent necessary for the communication with you. The legal basis for the described processing of your data insofar is Art. 6 para. 1 lit. b GDPR. The data collected in the context of your use of our online contact form will be deleted after processing of your query is finished without undue delay, unless we require such data for a longer period of time due to contractual or statutory obligations (cf. section “Duration of storage”).
You have the choice to register for our login area and enjoy the full functionality of our website. Mandatory fields are highlighted. This is your e-mail address and password. Without this data registration is not possible. Before completing the registration, we will use the “Double-Opt-In Procedure” described in section 3.2 above to confirm the email address you have provided and we will process your information as described there. The legal basis of the processing is Art. 6 para. 1 lit. b GDPR.
In an order process, we collect the necessary master data for contract fulfilment.
Optional details such as telephone and fax numbers can be stated, so we can contact you in case of queries also using these. With respect to the use of the e-mail address provided by you, we use the double opt-in procedure described in 3.2 above.
In addition, the information about the product you have purchased is stored and processed along with your master data.
As part of the payment process, we collect and process the necessary payment data according to the payment method you have selected. When paying by credit card, these are the card number, the expiration date and the security code (“CVC”). In the case of payment by electronic direct debit, these are the name of the account holder, the IBAN and the BIC or SWIFT.
The collection and processing of this data is necessary for the purpose of fulfilling the contract with you for the purchase of our products. We only process your data to the extent necessary for this purpose. The legal basis of the data processing is Art. 6 para. 1 p. 1 lit. b GDPR.
You have the option to subscribe to our newsletter, in which we keep you informed about new products and activities.
For the subscription to our newsletter, we use the double opt-in procedure described in 3.2. You can unsubscribe from the list anytime by using the respective unsubscribe link below every newsletter. Contacting us via mail or letter to the addresses given in the newsletter is of course also possible. The legal basis for data processing is your consent according to the Art. 6 Abs. 1 lit. a GDPR.
We are cooperating with the US service provider „MailChimp“ for sending out our newsletter and managing the mailing lists. MailChimp is a company of the Rocket Science Group, LLC, 512 Means Street, Suite 404 Atlanta, GA 30318 („MailChimp“). MailChimp is offering a comprehensive and technologically convincing software solution and the provider convinced us as an enterprise that takes responsibility for data security. They are certified under the EU US Privacy Shield and hence obliged to respect EU data protection policies. The subscriptions to our newsletter are transmitted to MailChimp and saved on the platform as long as you stay subscribed. As soon as you subscribe, you receive a confirmation mail to confirm your subscription. In this process, your IP address and the time of your subscription is saved by MailChimp.
In our newsletters, we use common technologies to track interactions with our mailings (such as openings and clicks). These data are used in an anonymized form to create statistics and optimize our content for the communication with our customers. This is done by using small graphics that are embedded in mailings (so-called pixels). These data are saved exclusively in an anonymized form and not matched with your personal data. The legal basis for this practice is our interest in building customized and optimized newsletters, confirm Art. 6 para. 1 S 1 lit. f GDPR. We want to share content that is relevant to our customers and understand better what our customers are interested in. If you do not wish for your usage to be analyzed, you can unsubscribe from our newsletter or deactivate graphics in your mailing program. The data on your interaction with our newsletter are saved under a pseudonym for thirty days and then anonymized fully.
2.6. Google Maps
Our website uses the map service Google Maps of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA („Google“). So the used Google map material can be embedded and shown in your browser, the browser has to establish a connection to a google server that could also be located in the US. In the case that personal data is transmitted to the US, Google has agreed to the EU-US Privacy Shield. Google thereby receives the information that our contact page was accessed from the IP address of your device. Legal basis Art. 6 para. 1 S. 1 lit. f GDPR, based on our legitimate interest in embedding a map service for building up contact.
If you access a Google map service via our website while logged into your Google account, Google can link this event to your Google profile. If you do not want this allocation, it is necessary to log out of your profile before accessing our contact page. Google saves your data and uses them for advertisement, market investigation and personalized map services. You can object to this to Google directly.
You can apply for available jobs by sending your application to our jobs e-mail address. The aim of saving the data is selecting applications for a possible employment relation. For receiving and processing your data, the following information are of particular interest to us: first and last name, e-mail address, application papers (references, CV), earliest possible starting day and payment wishes. The legal basis for processing your application are Art. 6 para. 1 S 1 lit. b and Art. 88 para. 1 of the GDPR.
2.8. Usage of own cookies
Some of our services require to use so-called cookies. A cookie is a small piece of text that is saved on your device by your browser. Cookies are not used to run programs or load viruses on your device. The main goal of our own cookies is rather to deliver a personalized offer for you and create a service that saves the most time possible for you.
Most browsers‘ standard settings accept cookies. You can, however, adapt your browser settings so that they reject cookies or only save them after prior consent. If you reject cookies, not all of our offerings might work without disturbances for you.
We use our own cookies particularly for
We want to enable a more comfortable and individual usage of our website for you. These services are based on our afore-mentioned legitimate interests, legal basis is Art. 6 para. 1 S. 1 lit. f GDPR.
2.9. Usage of cookies and similar technologies for analyses
The legal basis for data processing as described in the following is Art. 6 para. 1 S. 1 lit GDPR, based on our legitimate interest in creating an adapted user environment and continuous optimization of our web page.
In the following description of technologies we use, you can also find information on your revocation possibilities to our analyses measures via a so-called opt-out cookie. Please note that if you delete all cookies in your browser and use another browser or profile in the future, you have to use an opt-out cookie again.
2.9.1. Google Analytics
Google will process the information generated by cookies to evaluate the usage of the website, create reports on website activities for the website holders and offer further services connected to website and internet usage.
As stated above, you can configure your browser to reject cookies, or you can prevent the collection of the data generated by cookies and related to the usage of our website (incl. your IP address and the processing of this data by Google by using a browser add-on provided by Google. As an alternative to the browser add-on or when accessing our website from a mobile device, please use this opt-out link. This prevents the collection of data by Google Analytics on this website (the opt-out is only effective for this browser and domain). If you delete cookies in this browser, you have to activate the link again.
Further information can be found in Google’s data protection policy.
For the dispatch and the administration of our newsletter we use the US-provider “MailChimp”. MailChimp is a service of The Rocket Science Group, LLC, 512 Means Street, Suite 404 Atlanta, GA 30318 (“MailChimp”). MailChimp offers a well thought out and technically convincing software solution and the provider convinces as a secure and responsible company. They are certified under the EU-US Privacy Shield and is thus committed to comply with European data protection requirements. In view of the US data protection regulations, which deviate from the European requirements. The details of your subscription to the newsletter will be transmitted by us to MailChimp and stored there as long as you remain subscribed for the newsletter. After registering to receive the newsletter, you will receive a confirmation e-mail to confirm your subscription. In this context, your IP address and the time of your confirmation will be collected and stored by MailChimp.
2.10. Social Media Plug-Ins
Our website uses social media plug-ins (such as the like button) on the following social networks (also referred to as “social networks” below):
The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR, based on our legitimate interest that you share our content through social networks and we increase our reach.
In the event that personal information is transferred to the US, Facebook, and Twitter have been subject to the EU-US Privacy Shield. The social networks receive the information that you have accessed the corresponding subpage of our online service. This happens regardless of whether you have an account on one of the social networks and are logged in there. If you are logged in to one of the social networks, this data will be assigned directly to your local account. If you run the activated plug-in and for example, if you link the page, the social network will also store this information, including the date and time, in your user account and publicly disclose this to your contacts. If you do not want the association with your profile in the respective social network, you must log out before activating the plug-in.
The social networks store these data as usage profiles and use them for purposes of advertising, market research and / or tailor-made design of their websites. Such an evaluation is carried out in particular (also for non-logged-in users) for the presentation of needs-based advertising and to inform other users of the social network about your activities on our website. You have a right to object to the establishment of these user profiles, as Facebook members you can disable advertising based on social actions in the advertising preferences. You can also completely prevent the social media plug-ins of the social networks from being loaded with add-on programs for your browser, e.g. with the Facebook Blocker or the “Block third-party cookies” feature.
3. Disclosure of data
A transfer of the data collected by us takes place only if:
In addition, it may be disclosed in connection with government inquiries, court orders and legal proceedings if required for the prosecution or enforcement.
To process the data entered through our online contact form, we use the WordPress tool, a service of Automattic Inc. (60 29th St. # 343, San Francisco, CA 94110, USA, “Autmoattic”). In this regard, the data entered in our online contact form will be fed directly into our newsletter mailing list via WordPress. Insofar as your data is transferred to the US, Autmoattic has submitted to the EU-US Privacy Shield. The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR, based on our legitimate interest to process the data entered via the online contact form on our website safely and reliably by external service providers and at the same time to reduce our own effort for the provision of the IT infrastructure of our website.
4. Data retention time
As a matter of principle, we store personal data only as long as necessary to fulfill the contractual or legal obligations to which we have collected the data. Thereafter, we delete the data immediately, unless we need the data until the expiration of the statutory limitation period for evidence for civil claims or for statutory storage requirements.
For evidence, we must retain contract information for three years from the end of the year in which the business relationship ends with you. Any claims become statute-barred after the legal limitation period at the earliest at this time.
Even after that, we sometimes have to save your data for accounting reasons. We are obliged to do so because of legal documentation obligations which may arise from the German Commercial Code, the Tax Code, the Banking Act, the Money Laundering Act and the Securities Trading Act. The deadlines for storing documents are two to ten years.
5. Your rights
You have the right to request information about the processing of your personal data by us at any time. As part of the provision of information, we will explain the data processing and provide you with an overview of the data stored about you. If data stored by us should be incorrect or out of date, you have the right to have this information corrected. You may also request the deletion of your data. If deletion is not possible by way of exception due to other regulations, the data will be blocked so that they are only available for this legal purpose. You can also limit the processing of your data, such as: For example, if you believe that the information we hold is incorrect. You also have the right to data portability, this means that we will send you a digital copy of the personal data you provide on request.
To exercise your rights as described here, you can always use the contact details above. This also applies if you wish to receive copies of warranties to demonstrate adequate data protection.
In addition, you have the right to object to data processing, which is based on Art. 6 para. 1 lit. e or f GDPR is based. Finally, you have the right to complain to the Data Protection Authority responsible for us. You can assert this right with a supervisory authority in the Member State of your place of residence, your place of work or the place of the alleged breach. In Berlin, the headquarters of ubitricity, the competent supervisory authority is: Berliner Beauftragte für Datenschutz und Informationsfreiheit, (Berlin Commissioner for Data Protection and Freedom of Information), Friedrichstraße 219, 10969 Berlin.
6. Right of revocation and opposition
In accordance with Article 7 (2) of the GDPR, you have the right to revoke a consent once given to us at any time. As a result, we will not continue the data processing based on this consent for the future. The revocation of consent does not affect the legality of the processing carried out on the basis of the consent until the revocation.
Insofar as we process your data on the basis of legitimate interests in accordance with Art. 6 para. 1 lit. f GDPR, you have the right, in accordance with Art. 21 GDPR, to object to the processing of your data and to give us reasons that arise from your particular situation and that, in your opinion, speak in favor of your legitimate interests. If it concerns an objection against the data processing for purposes of the direct advertisement you have a general right of objection, which is implemented also without the indication of reasons for us.
If you would like to exercise your right of revocation or objection, it is sufficient to send an informal message to the above mentioned contact details.
7. Data Security
We maintain up-to-date technical measures to ensure data security, in particular to protect your personal data against dangers during data transfers as well as against access by third parties. These are adjusted according to the current state of the art. To secure the personal information you provide on our website, we use Transport Layer Security (TLS), which encrypts the information you provide.
8. Changes to the data protection policy
Version: 1.0 / Status: May 2018