Privacy notice

Last updated 29 September 2026

This notice explains how EnergyFlow handles personal data, in line with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and Romanian Law 190/2018. We collect as little as we can, never sell it, and don't use it for advertising.

1. Who we are

EnergyFlow (energyflow.ro) is operated by DEVOPS TEAM SRL, Str. Complexului nr. 3, Carcea, Dolj, Romania, fiscal code RO35610990, registered with the Trade Register under J16/276/2016 (“we”, “us”). For anything about your data, write to [email protected] or to the postal address above.

2. Our role

  • Controller — for visitors to this website and for the people who hold an EnergyFlow account (for example an installer's staff): we decide how that data is used.
  • Processor — for data about solar sites and their owners that an installer or other business customer puts into EnergyFlow. The business customer is the controller of that data; we process it only on their instructions and under a data processing agreement (Art. 28 GDPR), which is part of our Terms of service. If you are a system owner, your installer is your first point of contact, and we will help them answer your request.

3. What we collect

CategoryExamplesSource
Account dataName, email address, company, role, sign-in history, password (stored only as a hash by our sign-in service)You, or Google if you choose “Continue with Google”
Site dataSite name and address, map coordinates, system size and orientation, owner name and contact details entered by the installerOur business customer
Equipment dataInverter, battery, meter and charger models, serial numbers, settings, energy and power readings, alarmsInverter and device platforms you connect (e.g. Huawei, SMA, Fronius) or local gateways
Connection credentialsAccess tokens or logins for vendor platforms and smart-home systemsYou, when you connect an account
Support and communicationMessages, tickets and notes you send us or create in the appYou
Technical dataIP address, browser type, timestamps and error logsYour browser, automatically

Energy readings from a home can reveal patterns of daily life (for example when people are home). We treat them as personal data whenever they relate to an identifiable owner and protect them accordingly. We do not collect special categories of data (Art. 9 GDPR) and the service is not intended for children.

4. Why we use it, and on what legal basis

PurposeLegal basis (Art. 6 GDPR)
Creating and running your account, providing monitoring, diagnostics, forecasts, alarms and automationPerformance of a contract — 6(1)(b)
Sending service emails: alarms, daily digests, security and account messagesPerformance of a contract — 6(1)(b)
Keeping the service secure, preventing abuse, fixing faultsLegitimate interests — 6(1)(f)
Improving our detection models using aggregated or pseudonymised readingsLegitimate interests — 6(1)(f)
Invoicing, accounting and tax recordsLegal obligation — 6(1)(c)
Answering questions sent through the contact pageLegitimate interests — 6(1)(f), or steps before a contract — 6(1)(b)

Where we rely on legitimate interests you can object at any time (see Your rights). We make no decisions about people based solely on automated processing that produce legal or similarly significant effects. Automated alarms and recommendations concern equipment, not people.

5. Who receives data

We never sell personal data. We share it only with:

  • Hosting. Our servers, databases and backups run on infrastructure in the European Union that we operate ourselves.
  • Email delivery. Amazon Web Services (Amazon SES) sends our service emails.
  • Sign-in with Google, only if you choose it: Google receives the fact that you are signing in to EnergyFlow and gives us your name and email.
  • Weather data. Open-Meteo receives approximate site coordinates (no names or account details) so we can fetch local weather and produce forecasts.
  • Equipment platforms you connect (inverter vendors, Home Assistant, Tuya, EV charger platforms and similar). We send them your access credentials and, for automation, the commands you set up. They handle data under their own privacy terms.
  • Your installer or the business you share a site with, and anyone you give an owner share link to.
  • Authorities, when the law requires it, and professional advisers (accountants, lawyers) bound by confidentiality.

Every service provider acting for us is bound by a data processing agreement.

6. Transfers outside the EEA

Amazon SES processes service emails in the United States, and Google sign-in (if used) may involve transfers to the US. These transfers rely on the EU–US Data Privacy Framework where the recipient is certified, and on the European Commission's Standard Contractual Clauses otherwise. You can ask us for a copy of the relevant safeguards.

7. How long we keep it

  • Account data — while your account is open, then deleted within 90 days of closure.
  • Detailed energy readings — up to 3 years; daily and monthly totals — up to 5 years, so year-on-year performance can be compared. A business customer can ask for earlier deletion.
  • Vendor credentials — deleted as soon as you disconnect the platform or close your account.
  • Technical logs — up to 30 days, unless needed to investigate a security incident.
  • Invoices and accounting records — as long as Romanian tax law requires (currently up to 10 years).
  • Backups roll over and are overwritten within 30 days.

8. Security

All traffic is encrypted in transit (HTTPS/TLS). Vendor credentials are stored encrypted, access inside the app is limited to the account that owns a site, and staff access to production is restricted and logged. If a personal data breach is likely to put you at risk, we will tell the supervisory authority within 72 hours and inform the people affected, as the GDPR requires.

9. Cookies and local storage

We use only what is strictly necessary for the service to work, so no consent is needed and none is asked for. We use no analytics, advertising or social-media cookies.

NamePurposeDuration
ef_sessionKeeps you signed in (encrypted, HTTP-only)Up to 30 days
Sign-in service cookies (auth.energyflow.ro)Handle the login itself and protect it against forgerySession, or up to 30 days with “Remember me”
ef-themeRemembers your light/dark choice (local storage, never sent to us)Until you change it
ef-cookie-noticeRemembers that you have read the cookie notice (local storage)Until you clear it

You can delete cookies in your browser settings at any time; you will then need to sign in again.

10. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and get a copy of it;
  • have inaccurate data corrected;
  • have data erased, or its use restricted;
  • receive data you gave us in a machine-readable format and have it passed to another provider (portability);
  • object to processing based on legitimate interests;
  • withdraw any consent you gave, without affecting processing before withdrawal.

Write to [email protected]. We answer within one month, free of charge, and may ask you to confirm your identity first. You can also complain to the Romanian supervisory authority, Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București, www.dataprotection.ro, or to the authority in the EU country where you live or work.

11. Changes to this notice

When we change this notice we update the date at the top. If a change materially affects how we use your data, we will tell account holders by email before it takes effect.