Overview of data protection
Amphiro has set itself the goal of motivating consumers to use water and energy consciously and efficiently, to make the use of drinking water safer and to support companies in complying with compliance rules in the area of drinking water.
The collected data enables Amphiro to offer its products, services and apps (e.g. for smartphones, tablets or PCs) as well as its websites and helps it improve its offer, promote its marketing and develop new products.
The following information provides an overview of what happens to the personal information Amphiro collects about its users/visitors. Personal information is any information that personally identifies someone.
Data is collected when someone visits Amphiro’s website, uses its products (e.g. amphiro connect) and services (e.g. amphiro legionella alert) or apps. The user can find detailed information on the subject of data protection in the following data protection declaration.
Data collection on Amphiro’s website, in products, services and smartphone apps
Who collects the data?
The data processing is done by Amphiro. Anyone can find the contact details in the Legal Disclosure of this website. The data protection officer is also named there.
How does amphiro collect data?
Data is collected when users communicate with Amphiro. This may be done when sending a contact form or placing an order.
Other data is automatically collected by Amphiro’s IT systems when visitors enter the website. These are, for example, technical data (e.g. about the Internet browser, the operating system or the time of a page call or a command). This data is collected automatically as soon as a web page is viewed.
Further data is collected when customers install or use Amphiro’s products or apps. This can happen automatically after the installation of a device (e.g. to record energy consumption when using hot water) or as an input by users (e.g. when entering information about hot water heating in an app). Some functions in the app also require access to information provided by mobile phones, tablets or PCs. This includes, but is not limited to, information on the use of network connections. Access to the corresponding data provided by telephones only takes place after users have granted the app the necessary rights.
What do we use your data for?
Some of the data is collected in order to offer the full functions of Amphiro’s products, services and apps or to enable the purchase and delivery of its products. Other data may be used to analyze user behavior and improve website experience as well as products, services and apps.
In anonymous form, the data may also be shared with universities and research institutions for use in research and teaching. Before the data is passed on, it is ensured that no conclusions can be drawn about individual persons and that there is therefore no reference to identifiable persons.
The data can also be used anonymously to illustrate and advertise the functionality and effect of Amphiro’s products and services and the products associated with them. Prior to use, it is ensured that no conclusions can be drawn about individual persons and that there is therefore no reference to identifiable persons.
Furthermore, the names of companies in whose area of application the data is collected are only mentioned with their consent. The purpose mentioned in this section is also granted to the companies Hansa and Oras with the same obligations.
What rights do users have with regard to their data?
At any time, users/visitors have the right to receive information about the origin, recipient and purpose of their stored personal data – free of charge. Users also have the right to demand that this data be corrected, blocked or deleted. They can contact Amphiro at any time at the address given in the legal disclosure for this and other questions on the subject of data protection. Furthermore, users have the right to appeal to the responsible supervisory authority.
General information and mandatory information
Amphiro takes the protection of user’s personal data very seriously. Amphiro treats personal data confidentially and in accordance with the statutory data protection regulations and this data protection declaration.
Amphiro would like to point out that data transmission on the Internet (e.g. communication by e-mail or smartphone apps) and in general in communication networks (e.g. via Bluetooth) can have security gaps. A complete protection of the data against access by third parties is not possible.Responsible office
+41 (0)44 500 38 73
The responsible body is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (e.g. names, e-mail addresses, etc.).
Revocation of consent to the processing of data
Many data processing operations are only possible with the user’s express consent. Users can revoke their consent at any time. For this purpose, an informal e-mail notification to Amphiro is sufficient. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to file complaints with regulatory authorities
In the event of breaches of data protection law, the data subject shall have the right to lodge a complaint with the competent supervisory authority. The competent supervisory authority for data protection issues and its contact details can be found under the following link:
Right to data portability
Users have the right to have data automatically processed by Amphiro on the basis of user consent or in fulfilment of a contract handed over to the user or to a third party in a common, machine-readable format. If the user requests the direct transfer of the data to another responsible person, this will only be done as far as it is technically feasible.
SSL or TLS encryption
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or requests sent to Amphiro as the site operator. Visitors can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in the browser line. If SSL or TLS encryption is activated, the data transmitted to Amphiro cannot be read by third parties.
Encrypted payments on this website
If, after the conclusion of a contract with costs, there is an obligation to provide Amphiro with payment data (e.g. account number for direct debit authorization), this data is required for payment processing.
Payment transactions via the usual means of payment (Visa/MasterCard, direct debit) are carried out exclusively via an encrypted SSL or TLS connection. Users will recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in the browser line.
With encrypted communication, your payment data, which you transmit to us, cannot be read by third parties.
Information, blocking, deletion
Within the framework of the applicable legal provisions, users have the right at any time to free information about their stored personal data, their origin and recipient and the purpose of data processing and, if applicable, a right to correction, blocking or deletion of this data. Users can contact Amphiro at any time at the address given in the legal disclosure for this and other questions on the subject of personal data.
Opposition to promotional emails
Amphiro hereby object to the use of contact data published within the scope of the legal disclosure obligation to send unsolicited advertising and information material. The operators of this website expressly reserve the right to take legal action against unsolicited mailing or e-mailing of spam and other similar advertising materials.
Data collection on Amphiro’s website
Most of the cookies Amphiro uses are so-called “session cookies.” They are automatically deleted after a session is closed. Other cookies remain in devices’ memory until they are deleted. These cookies make it possible to recognize the browser when returning visitors next visit the site.
Server log files
The website provider automatically collects and stores information transmited automatically by the browsers in “server log files”. These include:
- Browser type and browser version
- Operating system used
- Referrer URL
- Host name of the accessing computer
- Time of the server request
- IP address
Should a user get in contact with Amphiro via the contact form, Amphiro will collect the data entered in the form, including the contact details provided, to answer the request and any follow-up questions. Amphiro does not share this information without permission.
Amphiro will, therefore, process any data entered into the contact form only with consent per Art. 6 (1)(a) DSGVO. Users may revoke their consent at any time. An informal email making this request is sufficient. The data processed before receiving a request may still be legally processed.
Amphiro will retain the data provided in the contact form until a user requests its deletion, revokes their consent for its storage, or the purpose for its storage no longer pertains (e.g. after fulfilling the request). Any mandatory statutory provisions, especially those regarding mandatory data retention periods, remain unaffected by this provision.
Registration on this website
Users can register on Amphiro’s website in order to access additional functions offered here. The input data will only be used for the purpose of using the respective site or service for which visitors have registered. The mandatory information requested during registration must be provided in full. Otherwise, Amphiro will reject the registration.
To inform users about important changes such as those within the scope of Amphiro’s site or technical changes, Amphiro will use the email address specified during registration.
Amphiro will process the data provided during registration only based on consent per Art. 6 (1)(a) DSGVO. Users may revoke their consent at any time with future effect. An informal email making this request is sufficient. The data processed before Amphiro receives the request may still be legally processed.
Amphiro will continue to store the data collected during registration for as long as the user remains registered on the website. Statutory retention periods remain unaffected.
Leaving comments on this website
When using the comment section on this site, the email address and the time of creation will be stored along with the comment, as well as the username, unless the comment is posted anonymously.
Storage of the IP address
Amphiro’s comment section stores the IP addresses of the users who post comments. Since Amphiro does not check comments before they are released on the website, Amphiro needs this information to be able to pursue action for illegal or slanderous content.
Longevity of comment storage
The comments and the associated data (e.g. IP address) are stored and remain on Amphiro’s website until the content commented has been completely deleted or the comments are required to be removed for legal reasons (slander, etc.).
The comments are stored based on consent per Art. 6 (1) (a) DSGVO. Users may revoke their consent at any time with future effect. An informal email making this request is sufficient. The data processed before Amphiro receives the request may still be legally processed.
Products for recording consumption data
Some of Amphiro’s products (e.g. amphiro basic) collect, store and transmit (e.g. amphiro connect) data on the use of water and hot water. The data includes flow rates, volumes, temperatures, energy quantities and energy efficiency levels, hot water heating efficiencies, the duration of withdrawals and pauses between withdrawals, and the number of withdrawals, consumption targets and efficiency ratings.
The products do not store names or addresses, but only an ID that allows assignment to one or more accounts. If the account(s) is/are deleted, the assignment is lost – the data thus loses its personal reference.
When users install and use an Amphiro app, the following personal data is collected:
- First name and surname.
Purpose: enable personal communication.
- E-mail ad-dress.
Purpose: contact users by e-mail, to confirm user account, to reset password, to provide reports and mailings. The e-mail also serves as a user name.
- IP address.
Purpose: ensu-ring the stability of the service.
- Location information.
Purpose: provide services such as consumption comparisons in the region, regional efficiency tips, provision of country-specific com-pliance information and reference values.
- Times of use.
Purpose: user motivation and calculation of averages.
- Age, gender.
Purpose: scientific purposes and market analysis.
- Type of client.
Purpose: differentiate between business and private customers to adapt functionality.
Purpose: enable simple communication.
- Desire to re-ceive newsletters.
Purpose: send newsletters for motivation and marketing.
- Information on motivation.
Purpose: wish to participate in efficiency challenges.
- Type of smartphone or tablet PC used.
Purpose: optimize service.
- All data collected by the products (e.g. am-phiro connect).
Purpose: offer of the service.
Access rights of the app
In order to provide services via the app, some end devices require an authorization to access location data in order to use Bluetooth.
Amphiro apps use encryption for security reasons and to protect the transmission of confidential content, such as requests sent to Amphiro as an app operator or communications between app users and Amphiro products. This encryption prevents or drastically complicates the possibility that the transmitted data be read by unauthorized third parties.
Processing of data (customer and contract data)
Amphiro collects, processes, and uses personal data only insofar as it is necessary to establish, or modify legal relationships (master data). This is done based on Art. 6 (1) (b) DSGVO, which allows the processing of data to fulfill a contract or for measures preliminary to a contract. Amphiro collects, processes and uses visitors’ personal data when they access Amphiro’s website (usage data) only to the extent required to enable them to access the service or to bill for the same.
Collected customer data shall be deleted after completion of the order or termination of the business relationship. Legal retention periods remain unaffected.
Data transmitted when entering into a contract with online shops, retailers, and mail order
Amphiro transmits personally identifiable data to third parties only to the extent required to fulfill the terms of your contract, for example, to companies entrusted to deliver goods to your location or banks entrusted to process your payments. Data will not be transmitted for any other purpose unless given express permission to do so. Data will not be disclosed to third parties for advertising purposes without express consent.
The basis for data processing is Art. 6 (1) (b) DSGVO, which allows the processing of data to fulfill a contract or for measures preliminary to a contract.
Facebook-Plugins (Like & Share-Button)
Amphiro’s website includes plugins for the social network Facebook, Facebook Inc., 1 Hacker Way, Menlo Park, California 94025, USA. The Facebook plugins can be recognized by the Facebook logo or the Like button on Amphiro’s site. For an overview of Facebook plugins, see Social Plugins.
If users do not want Facebook to associate their visit to Amphiro’s site with their Facebook account, they must log out of their Facebook account.
Functions of the Twitter service have been integrated into Amphiro’s website and app. These features are offered by Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. When using Twitter and the “Retweet” function, the visited websites are connected to the user’s Twitter account and made known to other users. In doing so, data will also be transferred to Twitter. Amphiro would like to point out that, as the provider of these pages, it has no knowledge of the content of the data transmitted or how it will be used by Twitter.
Privacy preferences with Twitter can be modified in the user’s account settings at Twitter account settings.
Amphiro’s website contains functions of the Pinterest social network, operated by Pinterest Inc., 635 High Street, Palo Alto, CA, 94301, USA.
When visiting a page containing the Pinterest social plugin, the browser establishes a direct connection to the Pinterest servers. The plugin transmits this log data to Pinterest servers in the United States. This log data may include IP address, the address of the websites visited, which also includes Pinterest features, browser type and settings, the date and time of the request, how Pinterest is being used, and cookies.
More information about the purpose, scope and further processing and use of data by Pinterest, as well as user’s rights and options to protect their privacy, can be found in the privacy notices of Pinterest: https://about.pinterest.com/de/privacy-policy.
Analytics and advertising
This website uses Google Analytics, a web analytics service. It is operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google Analytics uses so-called “cookies”. These are text files that are stored on computers and that allow an analysis of the use of the website. The information generated by the cookie about use of this website is usually transmitted to a Google server in the USA and stored there.
Google Analytics cookies are stored based on Art. 6 (1) (f) DSGVO. The website operator has a legitimate interest in analyzing user behavior to optimize both its website and its advertising.
Amphiro has activated the IP anonymization feature on this website. User’s IP addresses will be shortened by Google within the European Union or other parties to the Agreement on the European Economic Area prior to transmission to the United States. Only in exceptional cases is the full IP address sent to a Google server in the US and shortened there. Google will use this information on behalf of the operator of this website to evaluate your use of the website, to compile reports on website activity, and to provide other services regarding website activity and Internet usage for the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with any other data held by Google.
Users can prevent these cookies being stored by selecting the appropriate settings in your browser. However, Amphiro wishes to point out that doing so may mean users will not be able to enjoy the full functionality of this website. Visitors can also prevent the data generated by cookies about their use of the website (incl. your IP address) from being passed to Google, and the processing of these data by Google, by downloading and installing the browser plugin available at the following link: Google Analytics Opt-out Browser Add-on.
Objecting to the collection of data
Users can prevent the collection of their data by Google Analytics by clicking on the following link. An opt-out cookie will be set to prevent data from being collected on future visits to this site: Disable Google Analytics.
Demographic data collection by Google Analytics
This website uses Google Analytics’ demographic features.
This allows reports to be generated containing statements about the age, gender, and interests of site visitors.
This data comes from interest-based advertising from Google and third-party visitor data.
This collected data cannot be attributed to any specific individual person.
Users can disable this feature at any time by adjusting the ads settings in their Google account or the collection of data by Google Analytics can be forbidden as described in the section “Refusal of data collection”.
Users can object to the collection and use of their data at any time with future effect by clicking on this link and setting an opt-out cookie in your browser: Quantcast opt-out.
If visitors delete the cookies on their computer, they will have to set the opt-out cookie again.
Amphiro uses “Google reCAPTCHA” (hereinafter “reCAPTCHA”) on its website.
This service is provided by Google Inc., 1600 Amphitheater Parkway, Mountain View, CA 94043, USA (“Google”).
reCAPTCHA is used to check whether the data entered on this website (such as on a contact form) has been entered by a human or by an automated program. To do this, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis starts automatically as soon as the website visitor enters the website. For the analysis, reCAPTCHA evaluates various information (e.g. IP address, how long the visitor has been on the website, or mouse movements made by the user). The data collected during the analysis will be forwarded to Google.
The reCAPTCHA analyses take place completely in the background. Website visitors are not advised that such an analysis is taking place.
Data processing is based on Art. 6 (1) (f) DSGVO. The website operator has a legitimate interest in protecting its site from abusive automated crawling and spam.
To receive Amphiro’s newsletter, a valid email address as well as information that allows Amphiro to verify that the recepients are the owner of the specified email address and that they agree to receive this newsletter are required. No additional data is collected or is only collected on a voluntary basis. Amphiro only uses this data to send the requested information and does not pass it on to third parties.
Amphiro will, therefore, process any data entered into the contact form only with consent per Art. 6 (1) (a) DSGVO. Users can revoke consent to the storage of their data and email address as well as their use for sending the newsletter at any time, e.g. through the “unsubscribe” link in the newsletter. The data processed before Amphiro receives the request may still be legally processed.
The data provided when registering for the newsletter will be used to distribute the newsletter until the subscription is cancelled when said data will be deleted. Data we have stored for other purposes (e.g. email addresses for the members area) remain unaffected.
This website uses the services of MailChimp to send newsletters. This service is provided by Rocket Science Group LLC, 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA.
MailChimp is a service which organizes and analyzes the distribution of newsletters. If users provide data (e.g. your email address) to subscribe to Amphiro’s newsletter, it will be stored on MailChimp servers in the USA.
MailChimp is certified under the EU-US Privacy Shield. The Privacy Shield is an agreement between the European Union (EU) and the US to ensure compliance with European privacy standards in the United States.
Amphiro uses MailChimp to analyze its newsletter campaigns. When opening an email sent by MailChimp, a file included in the email (called a web beacon) connects to MailChimp’s servers in the United States. This allows Amphiro to determine if a newsletter message has been opened and which links you click on. In addition, technical information is collected (e.g. time of retrieval, IP address, browser type, and operating system). This information cannot be assigned to a specific recipient. It is used exclusively for the statistical analysis of Amphiro’s newsletter campaigns. The results of these analyses can be used to better tailor future newsletters to user’s interests.
Users refusing the analyzis of their newletter usage by MailChimp will have to unsubscribe from the newsletter. For this purpose, Amphiro provides a link in every newsletter it sends. Users can also unsubscribe from the newsletter directly on the website.
Data processing is based on Art. 6 (1) (a) DSGVO. Users may revoke their consent at any time by unsubscribing to the newsletter. The data processed before Amphiro receives the request may still be legally processed.
The data provided when registering for the newsletter will be used to distribute the newsletter until the subscription is cancelled, when said data will be deleted from Amphiro’s servers and those of MailChimp. Data stored by Amphiro for other purposes (e.g. email addresses for the members area) remains unaffected.
Payment service providers
This website accepts payments via Stripe. Stripe Payments Europe Ltd , Block 4, Harcourt Centre, Harcourt Road, Dublin 2, Ireland.
When selecting payment via credit card, the payment data provided will be supplied to Stripe based on Art. 6 (1) (a) (Consent) and Art. 6 (1) (b) DSGVO (Processing for contract purposes). The user has the option to revoke their consent at any time with future effect. It does not affect the processing of data previously collected.
Amendment of the Directive