Privacy notice
Last updated 29 September 2026
1. Who we are
EnergyFlow (energyflow.ro) is operated by DEVOPS TEAM SRL, Str. Complexului nr. 3, Carcea, Dolj, Romania, fiscal code RO35610990, registered with the Trade Register under J16/276/2016 (“we”, “us”). For anything about your data, write to [email protected] or to the postal address above.
2. Our role
- Controller — for visitors to this website and for the people who hold an EnergyFlow account (for example an installer's staff): we decide how that data is used.
- Processor — for data about solar sites and their owners that an installer or other business customer puts into EnergyFlow. The business customer is the controller of that data; we process it only on their instructions and under a data processing agreement (Art. 28 GDPR), which is part of our Terms of service. If you are a system owner, your installer is your first point of contact, and we will help them answer your request.
3. What we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, company, role, sign-in history, password (stored only as a hash by our sign-in service) | You, or Google if you choose “Continue with Google” |
| Site data | Site name and address, map coordinates, system size and orientation, owner name and contact details entered by the installer | Our business customer |
| Equipment data | Inverter, battery, meter and charger models, serial numbers, settings, energy and power readings, alarms | Inverter and device platforms you connect (e.g. Huawei, SMA, Fronius) or local gateways |
| Connection credentials | Access tokens or logins for vendor platforms and smart-home systems | You, when you connect an account |
| Support and communication | Messages, tickets and notes you send us or create in the app | You |
| Technical data | IP address, browser type, timestamps and error logs | Your browser, automatically |
Energy readings from a home can reveal patterns of daily life (for example when people are home). We treat them as personal data whenever they relate to an identifiable owner and protect them accordingly. We do not collect special categories of data (Art. 9 GDPR) and the service is not intended for children.
4. Why we use it, and on what legal basis
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Creating and running your account, providing monitoring, diagnostics, forecasts, alarms and automation | Performance of a contract — 6(1)(b) |
| Sending service emails: alarms, daily digests, security and account messages | Performance of a contract — 6(1)(b) |
| Keeping the service secure, preventing abuse, fixing faults | Legitimate interests — 6(1)(f) |
| Improving our detection models using aggregated or pseudonymised readings | Legitimate interests — 6(1)(f) |
| Invoicing, accounting and tax records | Legal obligation — 6(1)(c) |
| Answering questions sent through the contact page | Legitimate interests — 6(1)(f), or steps before a contract — 6(1)(b) |
Where we rely on legitimate interests you can object at any time (see Your rights). We make no decisions about people based solely on automated processing that produce legal or similarly significant effects. Automated alarms and recommendations concern equipment, not people.
5. Who receives data
We never sell personal data. We share it only with:
- Hosting. Our servers, databases and backups run on infrastructure in the European Union that we operate ourselves.
- Email delivery. Amazon Web Services (Amazon SES) sends our service emails.
- Sign-in with Google, only if you choose it: Google receives the fact that you are signing in to EnergyFlow and gives us your name and email.
- Weather data. Open-Meteo receives approximate site coordinates (no names or account details) so we can fetch local weather and produce forecasts.
- Equipment platforms you connect (inverter vendors, Home Assistant, Tuya, EV charger platforms and similar). We send them your access credentials and, for automation, the commands you set up. They handle data under their own privacy terms.
- Your installer or the business you share a site with, and anyone you give an owner share link to.
- Authorities, when the law requires it, and professional advisers (accountants, lawyers) bound by confidentiality.
Every service provider acting for us is bound by a data processing agreement.
6. Transfers outside the EEA
Amazon SES processes service emails in the United States, and Google sign-in (if used) may involve transfers to the US. These transfers rely on the EU–US Data Privacy Framework where the recipient is certified, and on the European Commission's Standard Contractual Clauses otherwise. You can ask us for a copy of the relevant safeguards.
7. How long we keep it
- Account data — while your account is open, then deleted within 90 days of closure.
- Detailed energy readings — up to 3 years; daily and monthly totals — up to 5 years, so year-on-year performance can be compared. A business customer can ask for earlier deletion.
- Vendor credentials — deleted as soon as you disconnect the platform or close your account.
- Technical logs — up to 30 days, unless needed to investigate a security incident.
- Invoices and accounting records — as long as Romanian tax law requires (currently up to 10 years).
- Backups roll over and are overwritten within 30 days.
8. Security
All traffic is encrypted in transit (HTTPS/TLS). Vendor credentials are stored encrypted, access inside the app is limited to the account that owns a site, and staff access to production is restricted and logged. If a personal data breach is likely to put you at risk, we will tell the supervisory authority within 72 hours and inform the people affected, as the GDPR requires.
9. Cookies and local storage
We use only what is strictly necessary for the service to work, so no consent is needed and none is asked for. We use no analytics, advertising or social-media cookies.
| Name | Purpose | Duration |
|---|---|---|
ef_session | Keeps you signed in (encrypted, HTTP-only) | Up to 30 days |
| Sign-in service cookies (auth.energyflow.ro) | Handle the login itself and protect it against forgery | Session, or up to 30 days with “Remember me” |
ef-theme | Remembers your light/dark choice (local storage, never sent to us) | Until you change it |
ef-cookie-notice | Remembers that you have read the cookie notice (local storage) | Until you clear it |
You can delete cookies in your browser settings at any time; you will then need to sign in again.
10. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and get a copy of it;
- have inaccurate data corrected;
- have data erased, or its use restricted;
- receive data you gave us in a machine-readable format and have it passed to another provider (portability);
- object to processing based on legitimate interests;
- withdraw any consent you gave, without affecting processing before withdrawal.
Write to [email protected]. We answer within one month, free of charge, and may ask you to confirm your identity first. You can also complain to the Romanian supervisory authority, Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București, www.dataprotection.ro, or to the authority in the EU country where you live or work.
11. Changes to this notice
When we change this notice we update the date at the top. If a change materially affects how we use your data, we will tell account holders by email before it takes effect.