1. Controller
The data controller for PV Dome is:
[FULL LEGAL NAME — COMPLETE BEFORE PUBLICATION][POSTAL ADDRESS — COMPLETE BEFORE PUBLICATION]
Berlin, Germany
Email: [CONTACT EMAIL — COMPLETE BEFORE PUBLICATION]
Website: https://pv-dome-energy.com
2. Data we process
- Account information, including email address, user identifier and authentication status.
- Organization membership and access role.
- Information you submit to the application, which may include names and business contact details entered in asset, owner or counterparty records.
- Technical information needed to deliver and secure the service, such as request, error and security logs produced by our infrastructure providers.
- Information included in messages you send to us.
Please use demonstration data only. Do not enter confidential information, personal data about third parties or real asset information unless expressly agreed with the provider.
3. Purposes and legal bases
- To create and maintain accounts, authenticate users and provide requested application functions: Article 6(1)(b) GDPR.
- To protect the application, prevent misuse, diagnose faults and maintain reliable operation: Article 6(1)(f) GDPR, based on our legitimate interest in operating a secure service.
- To respond to enquiries: Article 6(1)(b) or Article 6(1)(f) GDPR, depending on the enquiry.
- To meet legal obligations where applicable: Article 6(1)(c) GDPR.
4. Service providers and recipients
PV Dome currently relies on Supabase for authentication and database infrastructure, Vercel for application hosting and delivery, and IONOS for domain registration and/or DNS services. These providers may process limited personal or technical data when delivering their services. Their own privacy information describes their processing, locations and subprocessors.
We do not sell personal data and do not use it for advertising.
5. International transfers
Some providers or their subprocessors may process data outside the European Economic Area. Where required, transfers must rely on a lawful GDPR transfer mechanism, such as an adequacy decision or standard contractual clauses. The exact hosting region and provider arrangements will be reviewed before PV Dome handles production customer data.
6. Retention
Account and application data are retained while the relevant account or demonstration access remains active and for only as long afterwards as reasonably necessary for security, recovery or legal obligations. Enquiries are retained only as long as needed to answer and document them. Provider backups and security logs may follow separate limited retention cycles. More precise periods will be documented before commercial operation.
7. Security
PV Dome uses authenticated access and database row-level security to restrict organization data. No internet service is completely secure. During this MVP phase, users must not upload sensitive personal data, trade secrets or production credentials.
8. Your rights
Subject to the GDPR, you may request access, correction, deletion, restriction, portability or object to processing. Where processing is based on consent, you may withdraw it at any time. Contact the controller using the details above. You may also complain to a competent supervisory authority; for a controller established in Berlin, this is generally the Berlin Commissioner for Data Protection and Freedom of Information.
9. Automated decisions
PV Dome does not use personal data to make solely automated decisions that produce legal or similarly significant effects. Its portfolio and projection calculations are user-directed modelling outputs, not decisions about individuals.
10. Changes
This policy may be updated when the product, providers or data uses change. The current version and update date will remain available on this page.