Privacy Policy
1. Data Controller
The controller responsible for the processing of your personal data within the meaning of the General Data Protection Regulation (GDPR) is:
If you have any questions or concerns about how your data is processed, please contact us at the address above.
2. What Data We Collect
We collect and process the following categories of personal and operational data:
- Account data — your email address, name (if provided), and authentication identifiers, obtained via Auth0 when you sign in.
- Profile data — an optional avatar image you choose to upload. It is shown with your identity to authorised administrators and, when you share a sensor or station, to the owner and authorised access administrators of that resource.
- Sharing data — when access to a sensor or station is granted, the account name, email address, and assigned access level are shown only to the owner and authorised access administrators of that resource so they can identify users and manage access. If a user has uploaded an avatar, it is displayed in that restricted access-management context and loaded through an authenticated request.
- Sensor & IoT data — environmental measurements (temperature, humidity, CO₂, pH, LoRaWAN payload frames, etc.) that you upload to the platform through our ingest API or via a connected gateway.
- Device push tokens — if you use our iOS app and enable notifications, Apple issues a device-specific APNs push token which we store to deliver anomaly alerts to your device. This token cannot be used to identify you personally and is deleted when you disable notifications or delete your account.
- Usage & log data — server-side request logs including IP addresses, timestamps, HTTP status codes, and user-agent strings. These logs are used for security, abuse prevention, and operational monitoring. They are not used for advertising or behavioural profiling.
- Account administration data — your latest successful login and latest authenticated activity timestamp, assigned roles and permissions, and aggregated sensor activity. Access is restricted to authorised administrators and is used for account administration, support, platform security, and operational monitoring. The administration view does not create a detailed click history.
The Service is free of charge. We do not process any payment or billing data.
We collect only the data that is necessary for the operation of the service (data minimisation principle, Art. 5(1)(c) GDPR).
Account administration data is processed where necessary to provide and manage your account (Art. 6(1)(b) GDPR) and on the basis of our legitimate interest in operating the platform securely and reliably (Art. 6(1)(f) GDPR).
3. Auth0 as Identity Provider
Authentication is handled exclusively by Auth0, Inc. (an Okta company), headquartered at 1 Main Street, San Francisco, CA 94105, USA. When you sign in, your credentials are transmitted directly to Auth0's servers. We never see or store your password.
Our Auth0 tenant is hosted in Auth0's EU region, so authentication data is processed and stored within the European Economic Area. Auth0 acts as our processor under a Data Processing Addendum (DPA) that is incorporated into Auth0's subscription agreement and includes the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). In addition, Okta, Inc. and Auth0 are certified under the EU-U.S. Data Privacy Framework (including the UK Extension and the Swiss-U.S. DPF) for any residual transfers to the United States, such as support access (Art. 45 GDPR adequacy decision).
Auth0 processes your authentication data under its own privacy policy, which you can review at auth0.com/privacy.
The legal basis for this processing is the performance of a contract (Art. 6(1)(b) GDPR) — authentication is required to provide you with a secure, personalised account.
4. Other Service Providers (Processors)
We use a small number of additional service providers to operate the platform. Each acts as a processor on our behalf under Art. 28 GDPR:
- Cloudflare, Inc. — reverse proxy and DDoS protection in front of our servers. Cloudflare technically processes connection metadata (IP address, request headers) to route and protect traffic. Cloudflare is certified under the EU-U.S. Data Privacy Framework and offers EU Standard Contractual Clauses in its Data Processing Addendum. See cloudflare.com/privacypolicy.
- Amazon Web Services EMEA SARL (AWS) — AI-assisted anomaly analysis runs on Amazon Bedrock in the eu-central-1 (Frankfurt) region. Only sensor measurements and statistical context are sent for analysis; no account or contact data is included. Data does not leave the EU region.
- Apple Inc. (APNs) — if you use our iOS app with notifications enabled, anomaly alerts are delivered through the Apple Push Notification service using your device push token. See apple.com/legal/privacy.
The legal basis is the performance of a contract (Art. 6(1)(b) GDPR) and our legitimate interest in operating the service securely and reliably (Art. 6(1)(f) GDPR).
5. Sensor Data Storage
All IoT sensor data you upload — including time-series measurements from temperature, humidity, CO₂, pH, soil moisture, LoRaWAN frames, and any other sensor types — is stored on servers located in Regensburg, Germany, within the European Union.
Your sensor data is associated with your account and is accessible only to you and any team members you explicitly grant access to. Resource owners and authorised access administrators can see the name, email address, and access level of users listed for a shared sensor or station. Stations you mark as public will have their aggregated readings visible on the public map; no account-identifying information is attached to public readings.
The legal basis for storing your sensor data is the performance of a contract (Art. 6(1)(b) GDPR) — data ingestion and storage is the core function of the service.
6. Data Retention & Account Deletion
- Account data — retained for as long as your account is active. This includes only the latest login and activity timestamps used for account administration; no separate activity history is retained for the administration view. You can permanently delete your account and all associated data yourself at any time from Settings → Danger Zone (web) or Profile → Delete Account (iOS app), with no waiting period and no need to contact us. Deletion is immediate and irreversible: it cascades through your sensor values, anomalies, baselines, shares, follows, stations, devices, push tokens, and avatar, and also removes your Auth0 identity.
- Sensor data — retained on a rolling 12-month window. Measurements older than 12 months are automatically purged. You may delete individual stations or sensors at any time from your dashboard.
- Server logs — retained for up to 90 days for security and operational purposes, then deleted.
7. Your Rights Under the GDPR
As a data subject under the GDPR, you have the following rights with respect to your personal data:
- Right of access (Art. 15) — you may request a copy of all personal data we hold about you.
- Right to rectification (Art. 16) — you may ask us to correct inaccurate or incomplete data.
- Right to erasure (Art. 17) — you may request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
- Right to data portability (Art. 20) — you may request your sensor data and account data in a machine-readable format (JSON/CSV).
- Right to restriction (Art. 18) — you may request that we restrict processing while a dispute is resolved.
- Right to object (Art. 21) — you may object to processing based on legitimate interests.
To exercise any of these rights, contact [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the competent supervisory authority — in Bavaria, this is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach.
8. Location (iOS App Only)
The iOS app requests when-in-use location access solely to center the public station map on your current position. Your coordinates are processed locally on your device and are never transmitted to or stored on our servers. Station coordinates shown on the public map are set manually by the station owner, not derived from your device location.
9. Cookies
hydronode uses session-only cookies to maintain your authenticated session after sign-in. These cookies are:
- Set by Auth0 as part of the authentication flow (PKCE / OAuth 2.0).
- Stored only for the duration of your browser session unless you select "stay signed in".
- Strictly necessary for the service to function; no consent banner is required under GDPR Recital 47 for cookies that are technically essential.
We do not use advertising cookies, third-party tracking pixels, analytics cookies (e.g. Google Analytics), or any cross-site tracking technology.
10. Contact for Data Requests
For all data protection inquiries — including subject access requests, erasure requests, and portability exports — please write to:
Please include "GDPR Request" in the subject line along with a brief description of your request. We may ask you to verify your identity before acting on the request.