K2 Buddy App Data Protection Notice

You can download our K2 Buddy App to your smart phone as a mobile application. You can use it as a website on your electronic device. In this data protection notice, you will learn how we collect and process your personal data when you use either of the two methods mentioned above in connection with our K2 Buddy App. You will also learn how you can assert your claims and rights to which you are entitled under data protection legislation.

1. Who is the data controller and who can I contact (Data Protection Officer)?

The data controller is
K2 Systems GmbH (hereinafter referred to as “we”)
Haldenstraße 1
71272 Renningen-Malmsheim
Germany
Fax: +49 (0) 71 59 42 059 177
Directors: Katharina David, Willem Haag

You can contact the Data Protection Officer of our company at
K2 Systems GmbH
Data Protection Officer
Haldenstraße 1, 71272 Renningen-Malmsheim
Germany
datenschutz@k2-systems.de

1. What personal data do we process, for what purpose and on what legal basis?

a) When you access the K2 Buddy App website and mobile application

  • Operating system and access status of the mobile devices, as well as the browser, version and IP address (anonymised as standard). Device firmware versions and their contact status. User data such as the user name and e-mail address, but only for identification functions. The server log files are part of the access data that we collect when you access the website or app. We process this data so that we can take suitable technical measures in the event of an attack or disruption to our website or IT infrastructure, thus ensuring that the website or app continues to be operable. None of this data is merged with other data sources and this data is only accessed if there is reasonable suspicion of attacks on our infrastructure or if we require the data for troubleshooting purposes. The legal basis for this is Art. 6, para. 1 f of the EU General Data Protection Regulation (GDPR).

b) When you register via the central K2 User Service

To use the K2 Buddy App, you first need to register with and log into the central K2 User Service (MyK2). The details that we request during the registration enable us to give you access to the functions of the K2 Buddy App and allow you to use the app.The following link contains the general privacy policy of our central K2 User Service: https://k2-systems.com/en/digital-services/k2-user-service-data-protection-information/

c) When you use the K2 Buddy App

  • Location data (address of the PV system with a K2 Buddy device) and the device name, for documentation, to ensure a clear listing of your Buddies and to display them on a map; no tracking of the location takes place. The legal basis for this is Art. 6, para. 1 b GDPR.
  • Technical data, such as the necessary details about the PV system such as the roof type, roof covering, the installed mounting system, the cantilever to the edge of the module, data on the PV module such as dimensions and the correct load capacity for each clamping situation as well as the sensitivity of the sensors (push button cells) to ensure a proper and safe snow weighing function. The legal basis for this is Art. 6, para. 1 b GDPR.
  • Data that you have already entered during MyK2 registration (name, e-mail address) to enable the sending of e-mail notifications if the modules are overloaded. The legal basis for this is Art. 6, para. 1 b GDPR.
  • Date and time of your last setting of the system data (e.g. module load capacity) in order to have a comparison of the system data that may have been entered incorrectly at the time of the claim in the event of damage. Art. 6, para 1 f GDPR
  • Anonymised data that we collect for troubleshooting purposes (time, device number and error message). In addition, the requested, non-personal measured values such as raw sensor data are stored by us for three months, the total weight is stored for 12 months and the data is evaluated in pseudonymised form. We do so for the purpose of product development and optimisation and to optimise the software for the benefit of the user. We do not share stored data with third parties. The legal basis for this is Art. 6, para 1 f GDPR.

2. Cooperation with processors and third parties: with whom do we share your data?

Cooperation with processors and third parties

When we disclose or transmit data to processors or third parties or grant them access to your data by other means, we do so only if we have legal permission to do so (e.g. if the transmission of data to third parties is required to fulfil a contract under Art. 6, para. 1. b GDPR), if you have given your consent (Art. 6, para. 1 a GDPR), if this is required under a legal obligation (Art. 6, para. 1 c GDPR) or if we do so on the basis of our legitimate interests (e.g. when using agents, web hosting companies etc.) under Art. 6, para. 1 f GDPR. If we entrust third parties with the processing of data on the basis of a “processing contract”, this is done on the basis of Art. 28 GDPR.

We use the following companies as processors, who are each bound by a processing contract under Art. 28 GDPR and are strictly obliged to comply with data protection legislation. In particular, such companies are prohibited from disclosing your personal data to third parties outside this contract and from using such data for their own purposes:

  • OpenRemote, Netherlands (platform developer)

 

3. Do we disclose personal data to third countries (i.e. countries outside the EU and EEA)?

The hosting with regard to the personal data collected and processed when visiting this website and using the K2 Buddy App is done on AWS servers located in Ireland (EU), i.e. data is not transmitted to third countries in this regard.

 

4. How long do we store your data?

a) The server log files are erased automatically after a maximum of 30 days.

b) Any personal data generated by you that is required for the use of the K2 Buddy App will be stored by us until the account is deleted by the user. You can delete your account via our central K2 User Service. Please note that this also means that you will no longer have access to your Buddy’s measured values.
The following link contains the general privacy policy of our central K2 User Service: https://legacy.k2-systems.com/de/base-dashboard/datenschutz-user-service

 

5. Are you under an obligation to provide personal data?

You have no legal obligation to share your personal data. However, unless you provide such data, you will not be able to register for the app or make full use of its functions.

 

6. Do we use your data for profiling?

In accordance with Art. 22 GDPR, we do not use automated decision-making routines such as profiling while you register as a user or while you use the app.

 

7. What rights do you have?

You have the right at any time to request confirmation on whether we process your personal data and you are also entitled to access your personal data (Art. 15 GDPR). In addition, you have the right to rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of data processing (Art. 18 GDPR) as well as the right to data portability (Art. 20 GDPR).

________________________________________

Information on your right to object under Article 21 GDPR

You have the right on grounds relating to your personal situation to file an objection to the processing of personal data pertaining to you; you have this right at any time, with future effect on the basis of Art. 6, para. 1 e GDPR (data processing in the public interest) and Art. 6, para. 1 f GDPR (data processing based on a balance of interests).
If you file an objection, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for doing so – grounds which outweigh your interests, rights and freedoms – or unless processing serves the purpose of establishing, exercising or defending legal claims.
You can assert all rights with respect to us by e-mail at datenschutz@k2-systems.de or using the contact details listed in the section entitled “The data controller is”.
________________________________________

Furthermore, if you have any complaints under Art. 77 GDPR, you are entitled to contact the competent data protection supervisory authority. In our case, this authority is the State Officer for Data Protection and Freedom of Information (Landesbeauftragter für den Datenschutz und die Informationsfreiheit), Lautenschlager Str. 20, 70173 Stuttgart, Germany. You can usually also contact the competent data protection supervisory authority for your usual place of residence.

Additional information

Your trust is important to us. We are therefore happy to talk to you at any time and to answer any questions you may have concerning the processing of your personal data. If you have any questions that are not answered by this data protection notice or if you wish to receive further details on any of its aspects, please feel free to contact our Data Protection Officer at any time, using the contact details provided above.

Version 1.0 (last updated: 02-2024)