• Solarbroom Console
Solarbroom Console / Privacy Policy

Legal information

Privacy Policy

This policy explains how roofpower GmbH handles personal data when the Solarbroom web-interface, connected controllers, communications, and optional integrations are used.

Data controller and contact

The controller under the Swiss Federal Act on Data Protection and, where applicable, the EU General Data Protection Regulation is roofpower GmbH, Sonnenweg 14, 4415 Lausen, Switzerland.

Privacy requests can be sent to stephan.buess@roofpower.ch.

Account and access data

We process account identifiers and contact details, password hashes, roles, controller assignments and display names, language and notification choices, and account or access timestamps. This information is supplied by users or authorized administrators and is needed to create accounts, authenticate users, manage permissions, and provide the requested interface.

Web use, security, and operational monitoring

When the interface is visited or used, we process IP address, browser or device identification, timestamps, sign-in and session status, the last requested path or path category, dashboard or data stream type, and view opening, activity, and closing times. Relevant operational and security events may be associated with an account, session, or assigned controller.

For connected controllers, we also process connection status, connection and disconnection times, the connection address, outage information, disconnect reasons, and service-health measurements. Authorized operational personnel use this information for access control, account and service security, abuse investigation, outage notifications, troubleshooting, support, capacity planning, and reliable operation. It is not used for cross-site advertising or marketing profiles.

Controller and site data

Connected controllers may provide their identifiers and names, assignments, certificate and software status, configuration, command status, operating and sensor measurements, weather and location-related information, faults, events, diagnostic and maintenance information, and logged data requested for display or export. Authorized users see only controllers assigned to them; authorized administrators and support personnel may access additional information where needed to operate, secure, diagnose, maintain, or update the prototype system.

This information comes from users and administrators, the browser, connected controllers, and optional services selected for a controller.

Communications and optional integrations

We use email addresses and language choices for necessary account and security messages. Controller fault, connectivity, and service notifications follow the applicable preferences; product news is sent only where selected and can be disabled in account settings.

When an optional weather, map, or account-connection service is used, that provider receives the information required for the selected function. Depending on the function, this may include an authorization code or connection token, a station or module selection, a place-search term, coordinates or viewed map area, the user's IP address, and related weather observations. The provider processes that information under its own privacy terms.

Purposes and legal bases

We process personal data to provide and administer authorized prototype access; display, control, secure, diagnose, maintain, and improve the interface and connected controllers; deliver requested integrations and communications; comply with law; and establish, exercise, or defend legal claims.

Where the GDPR applies, the legal bases are performance of a contract or steps requested before a contract, compliance with legal obligations, and legitimate interests in safe and reliable service operation, security, support, prototype development, and protection of legal rights. We rely on consent where it is requested for an optional function or communication. Consent may be withdrawn for the future at any time.

Recipients and transfers abroad

Personal data is available only to authorized roofpower personnel and authorized users who need it for their role. We may disclose necessary data to processors providing hosting, infrastructure, email delivery, support, maps, weather or account connections, and to professional advisers or authorities where required or permitted by law. We do not sell personal data.

Processing may take place in Switzerland and, for selected providers, in countries of the European Economic Area and the United Kingdom. Before using a provider in another destination country, we will identify that destination and use an adequacy decision, recognized contractual clauses, or another lawful safeguard or exception as required. Current information about processors, destination countries, and safeguards can be requested at the privacy contact above.

Retention

Account, assignment, controller, certificate, and software records are kept while the account or controller is active and afterwards only for operational continuity, security, legal duties, or legal claims. Controller measurements, events, diagnostics, and communications are kept according to their operational purpose and configured retention, then deleted or anonymized where appropriate.

Closed operational-monitoring events, dashboard views, controller outages, and expired or revoked web sessions are generally retained for up to 90 days. Aggregated service-health measurements are generally retained for up to 30 days. Current controller connectivity information, including its latest connection address, may remain while that controller is registered. A longer period applies where evidence must be preserved for an incident, legal duty, or claim.

Rights and complaints

Depending on the applicable law, data subjects may request access, correction, deletion, restriction, objection, portability, or delivery of their personal data and may withdraw consent for future processing. These rights are subject to statutory conditions and exceptions. We may request information needed to verify identity.

Requests can be sent to the privacy contact above. A complaint may be made to the Swiss Federal Data Protection and Information Commissioner. Where the GDPR applies, a complaint may also be made to the competent EU or EEA supervisory authority.

Required information and automated decisions

Account, authentication, permission, and essential controller data are required to provide access and operate the requested service; without them, access or particular functions may not be available. Product-news preferences and optional integrations are voluntary.

We do not use the personal data described in this policy to make solely automated decisions about individuals that produce legal or similarly significant effects.

Security and policy changes

We use technical and organizational measures appropriate to the nature of the data and the prototype service, including access controls, protected communications, and security monitoring. No system can be guaranteed completely secure.

We may update this policy when the service, providers, or legal requirements change. The date shown below identifies the current version.

Last updated: 2026-08-03

This content was created with the assistance of AI tools.
  • Legal Notice
  • Privacy
  • Cookies
  • Terms

Solarbroom uses necessary cookies and browser storage for sign-in, security, and operation. No analytics or marketing cookies are used. Server-side operational records are described in the Privacy Policy.