SunEnergyXT Privacy Policy for the App
Effective date: September 2, 2026
Version: 2.0.0
1. Controller and Data Protection Officer
Safety Tax Free GmbH (“SunEnergyXT”, “we”, “us”, or “our”) provides the SunEnergyXT mobile application (the “App”) and the related App and Backend services (together, the “Services”).
The controller responsible for the processing described in this Privacy Policy is:
Safety Tax Free GmbH
Zeppelinstr. 33
85748 Garching bei München
Germany
Email: privacy@sunenergyxt.com
Our external Data Protection Officer is:
main-point consulting UG (haftungsbeschränkt)
Berger Str. 176
60385 Frankfurt am Main
Germany
Email: privacy@safetytaxfree.com
Where we process personal data strictly on behalf of another controller under a separate data processing agreement, we act as a processor only for that specific processing activity.
2. Scope of This Privacy Policy
This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you:
- create or use a SunEnergyXT account;
- connect, monitor, or manage a compatible photovoltaic, inverter, battery storage, wallbox, metering, or other energy device;
- create, join, or use a Space in the App;
- invite another user or an installer to access a Space;
- accept access to a Space shared by a user or installer;
- receive push and service messages; or
- contact customer support.
This Privacy Policy applies exclusively to the App and the related Services. A separate Privacy Policy applies to the SunEnergyXT website.
This Privacy Policy does not govern processing carried out independently by an installer or another recipient outside the SunEnergyXT Services. Where such a recipient acts as an independent controller, it is responsible for providing its own privacy information and identifying its own legal basis for processing.
3. Personal Data We Process
Depending on how you use the Services, we may process the following categories of personal data.
3.1 Account and Profile Data
- username, display name, or pseudonym;
- first and last name;
- email address, telephone number, and account identifier;
- company name and installer identifier, where applicable to an installer account;
- profile image;
- country, language, and time zone;
- authentication information, such as a securely stored password hash or authentication token;
- account type and verification status; and
- the version and time of the contractual and privacy information provided or acknowledged.
We do not disclose your account password or authentication credentials through the Space-sharing feature.
3.2 Space and Location Data
- Space name and description;
- address or city, country or region, and time zone associated with a Space;
- custom room, site, installation, or location names;
- Space ownership, administration, membership, and sharing status;
- electricity tariff, installed photovoltaic capacity, start date, system configuration, and other information entered for a Space; and
- where applicable, the location associated with a device or charging session.
With your permission, the App may temporarily use the current device location on your end device to suggest a city or address and to support certain Wi-Fi or Bluetooth setup functions. The raw coordinates used for this purpose are not transmitted to SunEnergyXT or stored by us. Only a city or address saved by you is transmitted to us as part of the Space. We do not derive your location from your IP address.
3.3 Device and Energy Data
- device and data logger identifiers, serial numbers, model, manufacturer, and device type;
- firmware and software version;
- connection, availability, and online status;
- device access, authorisation, and binding information;
- device settings, configuration, and operating status;
- photovoltaic generation, electricity consumption, grid import and export, charging and discharging, battery state of charge (SOC), and related measurements;
- for wallboxes, charging session, charging time, energy quantity, and related information;
- energy yield, savings, estimated revenue, trends, forecasts, and analyses;
- alarms, faults, warnings, event history, diagnostic information, and maintenance status; and
- timestamps and technical metadata associated with device measurements and control operations.
Energy data may reveal patterns relating to occupancy or use of a home or business. You should therefore grant access only to recipients you trust.
3.4 Network, Device, and Technical Data
- IP address, which is technically transmitted when communicating with our gateways and servers and may be processed depending on the relevant security and logging settings;
- Wi-Fi network name (SSID) and other network or access information required for device setup or operation;
- mobile device type, operating system, and App version;
- Apple Push Notification service token (APNs), Firebase Cloud Messaging token (FCM), Android ID, and, where applicable, Firebase Installation ID;
- device and data logger serial numbers;
- security, authentication, access, crash, and diagnostic logs; and
- information required to detect unusual traffic, attempted misuse, or unauthorised access.
Depending on the function used, the App may request access to location, camera, photos, Bluetooth, the local network, notifications, or files. These permissions are used only for the relevant function displayed to you, such as device setup, scanning a QR code, selecting a profile image, local device discovery, or receiving device alerts. Refusing a permission may prevent the relevant function from working but generally does not affect unrelated App functions.
3.5 Usage, Diagnostic, and Support Data
- limited functional events, in particular responses to rating prompts and events during tariff or device setup;
- login or account association of such functional events where they are triggered by a logged-in user;
- crash reports, App version, device model, operating system version, diagnostic identifiers, and technical error data;
- communications with customer support;
- files, screenshots, or other information that you voluntarily submit by email or through an available support channel; and
- records relating to support, installation, maintenance, or warranty requests.
We do not use an advertising identifier or cross-App or cross-company advertising tracking. General analytics of screen views, session duration, or user behaviour are not intentionally used. On Android, an embedded Firebase component may technically generate automatic diagnostic or basic events. We do not use such data for personalised advertising.
3.6 Marketing and Communications Data
Where you receive marketing communications or such communication is otherwise permitted by applicable law, we may process, in particular, your email address, display name or pseudonym, country or region, communication preferences, and limited account, device, and energy profile information. Service, security, and contractual communications are not marketing communications.
3.7 Space Invitation, Authorisation, and Audit Data
When a Space is shared, we process:
- account identifiers and roles of the inviting and invited parties;
- installer name, company, and installer identifier, where applicable;
- the Space and devices covered by the authorisation;
- the categories of information shared and permissions granted;
- timestamps for invitation, acceptance, rejection, expiry, and revocation;
- access and security logs; and
- where applicable, records of actions performed under the authorisation.
3.8 Data Received from Other Users or Installers
We may receive your email address, account identifier, installer identifier, or other invitation information from a user or installer who wishes to share a Space with you. We use this information exclusively to send, administer, secure, and document the invitation and resulting authorisation.
4. Required and Optional Information
An email address, password, and username or pseudonym are generally required to create a user account. A company name is additionally required for an installer account. Without this information, the relevant account cannot be created or used. First and last name, telephone number, and profile image are generally optional.
A Space name and country or region are required to create a Space. Information such as address or city, electricity price, installed photovoltaic capacity, or start date is generally optional; without this information, individual location-, tariff-, or statistics-related functions may be restricted.
The information required to connect a device depends on the device type. It may include, in particular, the target Space, a device or data logger serial number, a device name, Wi-Fi or device credentials, and an authorisation token. Without the connection information required for the relevant device, the device cannot be connected, provisioned, or controlled.
We record which versions of the Terms and Conditions and privacy information were provided and acknowledged during registration or use. Acknowledging this Privacy Policy does not constitute consent under data protection law. Where processing requires consent, we request it separately.
5. Purposes and Legal Bases
We process personal data for the following purposes and on the following legal bases under the General Data Protection Regulation (“GDPR”):
| Purpose | Categories Typically Used | Legal Basis |
|---|---|---|
| Create and administer your account | Account, profile, and technical data | Article 6(1)(b) GDPR |
| Connect, display, monitor, and support compatible devices | Space, device, energy, network, and technical data | Article 6(1)(b) GDPR |
| Create and administer Spaces | Account, Space, device, and authorisation data | Article 6(1)(b) GDPR |
| Send, accept, administer, and revoke Space invitations and provide shared viewing, control, parameter-change, and device-deletion functions | Account, Space, device, energy, invitation, action, and audit data | Article 6(1)(b) GDPR, performance of a contract at the user’s request |
| Installation, diagnostics, maintenance, and requested customer support | Device, energy, diagnostic, support, and authorisation data | Article 6(1)(b) GDPR; where applicable, Article 6(1)(f) GDPR |
| Send push, service, security, and contractual communications | Account, device, contact, push, and technical data | Article 6(1)(b) and, where applicable, Article 6(1)(c) or (f) GDPR |
| Protect accounts, devices, and Services and prevent fraud and misuse | Account, technical, network, authorisation, and audit data | Article 6(1)(f) GDPR; where necessary, Article 6(1)(c) GDPR |
| Error diagnosis, technical functionality testing, and improvement of the Services | Functional, crash, diagnostic, and technical data and aggregated or pseudonymised device data | Article 6(1)(f) GDPR |
| Send marketing communications and manage marketing preferences | Email address, profile and communications data, and, where applicable, limited device or energy profile information | Article 6(1)(a) GDPR; where the statutory requirements for existing-customer communications are met, Article 6(1)(f) GDPR in conjunction with Section 7(3) UWG |
| Establish, exercise, or defend legal claims and comply with legal obligations | Relevant account, authorisation, support, transaction, and audit data | Article 6(1)(c) and (f) GDPR |
Where we rely on legitimate interests, these interests include, in particular, providing the Services securely, reliably, and in a user-friendly manner, troubleshooting, preventing misuse, and defending legal claims. We balance these interests against your rights and reasonable expectations. You may object to the processing as described in Section 12.
6. Space Sharing and Installer Access
6.1 How Sharing Works
A Space Owner or Space Administrator may invite a selected registered and verified SunEnergyXT user or installer (the “Authorised Party”) to access a Space. An authorisation becomes active only after the recipient accepts the invitation through the App or another secure method provided by us.
An installer may also share a Space it is authorised to administer with a selected user. Before acceptance, the App displays the parties involved, the relevant Space, and the applicable scope of permissions.
6.2 Data and Functions Made Available
Depending on the permissions displayed in the App and granted by the Space Owner or Space Administrator, an Authorised Party may:
- view Space information and information relating to devices assigned to the Space, including device status, measurements, energy data, settings, alarms, faults, and historical information;
- send control commands to a device;
- modify device parameters or operating settings; and
- remove or delete a device from the Space or the relevant account association.
These permissions do not transfer ownership of a Space, physical device, account, or data. An Authorised Party may invite additional recipients only where the App separately provides that permission and the Space Owner or Space Administrator expressly grants it.
6.3 Responsibilities of the Parties Involved
The party granting access must be authorised to administer the Space and devices and to make the relevant data available. Where Space or energy data relate to household members, co-owners, tenants, employees, customers, or other persons, an appropriate legal basis or permission for sharing must exist.
An Authorised Party may use shared data and operating permissions only for the purpose for which access was granted, such as installation, commissioning, monitoring, diagnostics, maintenance, or support. Control commands, parameter changes, and device deletions must remain within the granted authorisation. The recipient must not use shared data for unrelated marketing, sale, profiling, or onward disclosure without a separate legal basis.
An installer that determines the purposes and means of processing generally acts as an independent controller for that processing. An installer acting exclusively on the documented instructions of another controller may act as a processor; where required, a data processing agreement must be concluded under Article 28 GDPR.
6.4 Revocation and Expiry
Both the party granting access and the Authorised Party may revoke the authorisation or leave the Space at any time through the App. Revocation generally terminates future access through the Services immediately once the technical process is complete. It does not affect the lawfulness of processing carried out before revocation.
An authorisation also ends when it expires, the relevant account or Space is deleted, the Space relationship ends, or we suspend access for security, legal, or contractual reasons.
7. Recipients of Personal Data
We disclose personal data only where necessary for the purposes described. Not every service listed below processes data relating to every user. The device platform used depends, in particular, on the connected devices.
7.1 Users and Installers Selected by You
We disclose Space and device data to an Authorised Party only after completing the sharing and acceptance process described in Section 6. Before authorisation, limited identity and invitation information may be disclosed so that the parties can recognise each other and decide whether to proceed.
7.2 Hosting, Communications, Development, and Technical Operations
- Amazon Web Services (AWS): hosting, IoT connectivity, databases, file storage, device-data storage, and technical infrastructure; the main systems are operated in Frankfurt am Main.
- AWS Simple Email Service: sending registration, verification, alert, and other service emails through the Frankfurt region.
- Firebase Cloud Messaging (Google): sending push notifications to Android devices; the data processed includes, in particular, push tokens, notification content, and necessary device information.
- Apple Push Notification service: sending push notifications to Apple devices; the data processed includes, in particular, push tokens, notification content, and necessary device information.
- Firebase Crashlytics (Google): technical crash diagnostics on iOS and Android; the data processed includes, in particular, crash reports, App and device information, operating system version, and diagnostic identifiers.
- Xiao Mu (Beijing) TECHNOLOGY CO., LTD. and the development and technical team working for SunEnergyXT in China and Hong Kong: development, maintenance, and technical error analysis. Where necessary, limited account, Space, device, telemetry, log, and support data may be accessed through controlled and logged access systems.
- Permission-controlled logging system in Hong Kong: storage of operational logs that have been masked or cleansed of sensitive fields for error analysis and customer-support purposes.
7.3 Device and Integration Platforms
Depending on the connected devices, we use the following technical platforms:
- Solarman/iGEN and Deye: device provisioning, authorisation, binding, cloud connectivity, telemetry, status, and alert processing for supported devices. The data processed includes, in particular, device and data logger serial numbers, product information, authorisation and binding status, required device credentials, telemetry, and alerts. Some technical endpoints are located in Europe; the platform providers are based, or may also provide access, outside the EEA.
- Quectel: provisioning and cloud integration for supported devices or modules; the data processed includes, in particular, serial numbers, device status, and data required for provisioning and operation.
- APsystems: integration of micro-inverter telemetry, alerts, and production data; the data processed includes, in particular, device identifiers, energy and telemetry data, and alerts.
- TSUN: provisioning, telemetry, and control of supported micro-inverters; the data processed includes, in particular, device identifiers, provisioning, telemetry, and control data.
- StarCharge/EN+: integration of supported wallboxes and processing of charging sessions; the data processed includes, in particular, wallbox identifiers, authorisation information, charging time, energy quantity, location, and charging-session data.
- everHome/EcoTracker: integration of supported smart meters; the data processed includes, in particular, device identifiers, authorisation tokens, and power measurements.
- Rabot Charge: integration of dynamic tariffs and contract status; the data processed includes, in particular, tariff-contract status and data required for account linking.
- Highpower: processing of battery alerts, statistical reports, and information relating to previous device updates; the data processed includes, in particular, device model, device identifiers, alerts, statistical data, and update-related information. Information may be transferred to China in this context.
7.4 Marketing Service Provider
- Klaviyo: sending and managing permitted marketing communications and synchronising user profiles. Depending on use, the data processed may include, in particular, email address, pseudonym, country or address, device information, phone model, operating system, and limited energy and profile information. Processing may take place in the United States.
7.5 Other Recipients
We may also disclose data:
- to professional advisers, auditors, insurers, and legal representatives where necessary;
- to public authorities where disclosure is required by law or a binding legal order;
- to protect the rights, security, and integrity of users, devices, the public, or the Services; or
- in connection with a merger, restructuring, financing, acquisition, or transfer of a business operation, subject to appropriate confidentiality and notice obligations.
8. International Data Transfers
Our main systems are generally operated in Frankfurt am Main. However, in connection with development, technical operations, logging, push communications, marketing, and the integration of certain device platforms, personal data may also be processed in or accessed from China, Hong Kong, the United States, or other countries outside the European Economic Area.
Where the country concerned is not covered by an adequacy decision of the European Commission, we use a permitted transfer mechanism, in particular the European Commission’s Standard Contractual Clauses, and implement supplementary technical and organisational safeguards where required. These may include access restrictions, logging, encryption, and masking sensitive log fields. You may contact privacy@sunenergyxt.com for further information about the applicable safeguards or to request a copy of the relevant provisions; necessary redactions remain reserved.
9. Data Retention and Account Deletion
We retain personal data only for as long as necessary for the purposes described and to meet legal, security, and contractual requirements.
- Account data are generally retained for the duration of account use. When an account is deleted, login tokens are invalidated and access to the account is terminated. Spaces, device relationships, device data, and Strategy data associated with the account are deleted from active business systems unless overriding reasons prevent this. Individual account fields and audit logs may remain temporarily in access-restricted form where necessary for security, technical processing, legal obligations, or legal claims.
- When a Space or device is deleted, the related Space information, device relationships, device master data, historical telemetry, and Strategy data are deleted from the primary business databases once the deletion process is complete.
- Restricted backup copies may remain until the relevant backup cycle expires, currently generally for up to three years. They are not used for ongoing operations.
- Data relating to active Space authorisations are retained for the duration of the authorisation.
- Invitation, revocation, access, control-command, parameter-change, device-deletion, and security logs are retained for as long as necessary to document authorisations, maintain system security, investigate incidents, or defend legal claims. Regular Space authorisation logs are intended to be deleted or anonymised no later than 24 months after the authorisation ends unless a justified exception applies.
- Internal logs recording access to production systems are generally retained for up to three years.
- In-App messages and related notification records are generally deleted after three months.
- Support communications are retained while the request is being handled and subsequently for as long as necessary for service quality, warranty matters, or legal claims.
- Marketing preferences are retained until you withdraw your consent, object to processing, or the information is no longer required. A minimal suppression record may be retained to ensure that your choice continues to be respected.
- Data held by device platforms and other service providers are additionally subject to their contractually agreed deletion and backup cycles.
You may initiate account deletion in the iOS App under “Settings – Account – Delete Account” and in the Android App through the account page. You may also contact us at privacy@sunenergyxt.com. If the account is still part of an active Space authorisation, that relationship may need to be terminated first.
Account deletion does not necessarily result in the immediate physical deletion of every technical copy. Where data must be retained temporarily, we restrict access and use to the relevant retention purpose and delete or anonymise the data once that purpose no longer applies.
10. Security
We implement technical and organisational measures appropriate to the relevant risks. These include access controls, role-based permissions, encryption in transit, protected storage of credentials, logging, monitoring, and procedures for responding to security incidents.
Access to production data by development and technical personnel takes place through controlled and logged systems. Access is read-only by default; changes require separate approval. User passwords are stored as hashes, and required device credentials are stored in encrypted form.
You are responsible for keeping your account credentials confidential, verifying the identity of the intended recipient before sharing a Space, regularly reviewing active authorisations, and revoking access that is no longer required. No method of storage or transmission provides absolute security.
11. Data Relating to Other Persons
If you provide information about another person or grant access to data relating to another person, you must be authorised to do so and must provide any information required by law. You must not use the Services to disclose personal data unlawfully.
Where we receive invitation data relating to a person who is not yet registered, we use it exclusively to carry out and secure the invitation. The privacy information is made available in connection with the invitation or no later than the first contact.
12. Your Rights
Subject to the applicable legal requirements, you may have the right to:
- obtain information about your personal data and receive a copy of those data;
- have inaccurate or incomplete data corrected;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests or to direct marketing;
- receive data you provided in a structured, commonly used, and machine-readable format and transmit those data to another controller;
- withdraw consent at any time with effect for the future; and
- lodge a complaint with a competent data protection supervisory authority.
You may separately revoke a Space authorisation through the App. Revoking a Space authorisation is not the same as withdrawing consent under the GDPR or deleting your account.
To exercise a data protection right, contact privacy@sunenergyxt.com. We may request information necessary to verify your identity and protect your account.
13. Connected Product Data and the EU Data Act
Where Regulation (EU) 2023/2854 (the “EU Data Act” or “Data Act”) applies to a connected product or related service, users may have statutory rights to access data generated through their use of the product or service and request that such data be made available to a third party of their choice. Space sharing is one way to share relevant data; however, it does not limit any mandatory rights under the EU Data Act.
The EU Data Act does not replace the GDPR. Where connected-product data contain personal data, the GDPR and other applicable data protection requirements continue to apply.
14. Children
The Services are not directed at children. Persons who are not legally able to enter into the relevant user agreement independently may use the Services only with the involvement and consent of a parent, guardian, or other legal representative. We do not knowingly use children’s personal data for marketing or profiling.
15. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to the Services, processing activities, legal requirements, or security requirements. We will notify existing users in advance by email to the address registered to their account of material changes. The notice will identify the updated Privacy Policy, the material changes, and the date on which they take effect.
Where a new processing activity requires consent, we will obtain your explicit consent before starting that processing. Continued use of the Services will not be treated as consent where applicable law requires an affirmative indication of consent.
The effective date and version number at the beginning of this Privacy Policy identify the current version.
16. Contact and Imprint
For questions about this Privacy Policy or to exercise your rights, contact:
Email: privacy@sunenergyxt.com
Safety Tax Free GmbH
Zeppelinstr. 33
85748 Garching bei München
Germany
Managing Director: Chengyuan Zhai
Registry Court: Amtsgericht München
Registry Number: HRB 225103
VAT ID No.: DE306117575