/
Privacy Policy – reev Products

Privacy Policy - reev Products

This Privacy Policy explains how personal data is processed in connection with the products and services of reev GmbH. reev processes only such data as is necessary to provide and secure the respective services, applying the principle of data minimisation. “Personal data” means any information relating to an identified or identifiable natural person (data subject), such as name, address, telephone number, date of birth, email address or IP address. Information that cannot be attributed to a particular person, for example as a result of anonymisation, is not regarded as personal data.

This Privacy Policy applies to the following products and services:

  • reev Energy Hub (formerly reev Dashboard)
  • reev Living
  • reev App
  • reev Direct Pay (formerly reev Ad-hoc)
  • reev Payment Terminal
  • reev Companion (formerly eWizard)
  • reev Companion Plus (formerly reev Partner Portal)
  • reev Stromtarif

1. Controller

Use within the scope of your employment relationship or contract with a reev business customer

Where your employer or a company (e.g. a car park or fleet operator) provides the reev charging solution, that company is responsible for what happens to your data. In this case, reev acts only on behalf of that company and may process your data solely on the company’s instructions.

This applies to the following reev products: the reev App, the reev Energy Hub, the reev.one web portal, the reev Payment Terminal, as well as reev Companion and reev Companion Plus.

Exception: In certain cases, for example where the account data of administrators or the company’s own contract with reev is concerned, reev is itself the controller of the data. These cases are marked separately in Section 4 of this Privacy Policy.

Independent / private use of the reev App or reev.one

If you use the reev App or reev.one independently from the relevant app store / via the web, without a company having introduced reev for you or having required you to use it, reev is itself the controller for the processing of your personal data. In this case, we provide our services (e.g. management of your user account, recording and analysis of your charging sessions, payment processing) directly to you on the basis of the usage relationship between you and reev.

Ad-hoc payment at the reev Payment Terminal

If, as an ad-hoc driver, you charge by debit or credit card directly at the terminal of a charging station without creating a user account with reev, reev is itself the controller for the payment processing arising in this context.

Joint controllership – reev Stromtarif

For processing within the scope of the product “reev Stromtarif”, reev and Nomos GmbH are joint controllers within the meaning of Art. 26 GDPR. For further details, see Section 4.7.

Contact details of reev GmbH:

reev GmbH

Sandstraße 3

80335 Munich

Germany

Phone: +49 (0) 89 21538970

Email: privacy@reev.com

 

2. Data protection officer

reev has appointed as its data protection officer: :

Kertos GmbH

Brienner Str. 41

80333 Munich

Email: dataprivacy@kertos.io

3. General Information

 
3.1 Legal bases

We process your personal data only where there is a legal basis for doing so. The following are particularly relevant:

  • Art. 6(1)(a) GDPR – consent
  • Art. 6(1)(b) GDPR – performance of a contract / pre-contractual measures
  • Art. 6(1)(c) GDPR – compliance with a legal obligation
  • Art. 6(1)(f) GDPR – legitimate interests
  • Art. 28 GDPR – processing on behalf of the customer
  • Art. 26 GDPR – joint controllership (reev Stromtarif)
  • Section 25 TDDDG – access to, or storage of, information on terminal equipment
 
3.2 Encryption

For security reasons, our platforms, apps and websites use SSL/TLS encryption. You can recognise an encrypted connection by the padlock symbol or by the https:// in the address bar of your browser.

3.3 Hosting infrastructure

All reev products are hosted on the cloud infrastructure of Amazon Web Services (Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg). We have concluded a data processing agreement with Amazon Web Services. The server location is in the EU (in particular Frankfurt and Ireland).

4. Processing activities

 
4.1 reev Energy Hub

The reev Energy Hub is a SaaS application through which customers manage charging infrastructure, driver accounts, (energy) tariffs and billing. In this respect, reev is the customer’s processor (Art. 28 GDPR); for the establishment of the customer contractual relationship and the master data of the administrators, reev is itself the controller. The sub-processors engaged are set out in the respective processing descriptions.

 
4.1.1 Provision and hosting of the Energy Hub

Processing on behalf within the meaning of Art. 28 GDPR.

Purpose: provision of the reev Energy Hub as software-as-a-service, storage of the data uploaded by the customer

Data processed:

  • usage data (e.g. IP address, date and time of the request)
  • master and contact data of the administrators (name, business email, telephone, role)
  • master, contract and infrastructure data uploaded by the customer
  • technical log data (request/response data, error messages)

 

Legal basis: Art. 6(1)(b) GDPR (performance of the contract with the customer or administrator); Art. 6(1)(f) GDPR (ensuring operation)

Storage period: For the duration of the usage relationship; thereafter erasure in accordance with the data processing agreement or upon expiry of statutory retention periods.

 
4.1.2 Login and user management

For the customer’s administrators, reev processes as controller; for the driver/employee accounts created by the customer, as processor.

Purpose: authentication (login) and management of user profiles on the reev Energy Hub

Data processed:

  • login data (email address, password)
  • authentication data (IP address, login times, session ID)
  • profile information (first and last name, role, optionally telephone number)
  • system and session data (login time, device type, browser used)

 

Legal basis: Art. 6(1)(b) GDPR (performance of the contract); Art. 6(1)(f) GDPR (secure authentication and access protection)

Storage period: Storage for the duration of the active user account or until erasure by the user or the customer; thereafter erasure within the customary period (as a rule, no more than 180 days).

4.1.3 Activation of the chargeable Energy Hub access

For B2C customers, reev is itself the controller (Art. 4(7) GDPR). The processing is carried out for the initiation and performance of the direct SaaS contract between reev and the B2C customer. For B2B customers, reev acts as a processor pursuant to Art. 28 GDPR.

Purpose: activation of the chargeable Energy Hub access within the scope of self-service onboarding for non-enterprise customers. The activation process comprises registration (sign-up), acceptance of the General Terms and Conditions and the mandatory provision of a payment method. Full access is enabled only after these steps have been completed.

Recipient(s): Stripe Payments Europe, Limited, Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (for legally mandated processing operations (PSD2/ZAG, anti-money-laundering/sanctions-list screening), Stripe also acts as a separate controller)

Data processed:

  • company data (company name, address, legal form, where applicable VAT ID)
  • master and contact data of the contractual contact person (first and last name, function, business email address, telephone number)
  • login data (email address, password)
  • means of payment and payment-method data (e.g. credit card data, IBAN/BIC or other payment methods supported by Stripe – encrypted transmission to Stripe)
  • tokens and transaction metadata from the payment-method verification
  • authentication data within the scope of the 3D Secure 2.0 check
  • evidence and timestamp of acceptance of the General Terms and Conditions (including the version of the Terms)

 

Legal basis: Art. 6(1)(b) GDPR (initiation and performance of the SaaS contract with the B2C customer); Art. 6(1)(c) GDPR in conjunction with PSD2 (Directive (EU) 2015/2366) and the ZAG (strong customer authentication ; anti-money-laundering and sanctions law) as well as in conjunction with commercial and tax-law obligations ; Art. 6(1)(f) GDPR (fraud prevention and secure payment transactions)

Storage period:For the duration of the contractual relationship; upon termination of the contract, erasure in accordance with internal policies. Contract, payment and invoice data are retained in accordance with commercial and tax-law retention obligations (as a rule, 10 years). Stored means of payment are retained for as long as they are actively on file, but at the latest until termination of the contractual relationship.

 
4.1.4 Processing of charging infrastructure, consumption and charging-session data

Processing on behalf of the customer (Art. 28 GDPR).

Purpose: management of charging stations and charging groups, authorisation and allocation of charging sessions, billing as well as, where applicable, the handling of the trading of greenhouse-gas reduction quotas

Recipient(s): Stripe Payments Europe, Limited, Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (for legally mandated processing operations relating to payment transactions (strong customer authentication pursuant to PSD2/ZAG, anti-money-laundering/sanctions-list screening, fraud prevention), Stripe also acts as a separate controller)

Data processed:

  • master and contact data of the driver (first and last name, billing address, email address, optionally telephone number)
  • email address, RFID tag number, charge card number and name of the card
  • account details (account holder, IBAN) – in so far as required for billing or the GHG quota
  • means of payment and payment-method data (e.g. credit card data, IBAN/BIC, where applicable other payment methods supported by Stripe)
  • payment and transaction data (amount, currency, time, payment status, tokens, transaction IDs)
  • authentication data within the scope of the 3D Secure 2.0 check
  • scan of the vehicle registration document (for the GHG quota)
  • vehicle data of company vehicles (registration number, RFID tag number, optionally manufacturer/make)
  • data on charging sessions (station, connector, start/end, energy charged, status, tariff)

 

Legal basis: Art. 6(1)(b) GDPR; processing is carried out on behalf of the customer (Art. 28 GDPR); Art. 6(1)(c) GDPR in conjunction with PSD2 (Directive (EU) 2015/2366) and the ZAG (strong customer authentication, anti-money-laundering and sanctions law) as well as in conjunction with commercial and tax-law retention obligations; Art. 6(1)(f) GDPR (fraud prevention and secure payment transactions).

Storage period: For the duration of the usage or contractual relationship between the driver and the customer; thereafter erasure in accordance with the requirements of the data processing agreement or upon expiry of statutory retention periods.

 
4.1.5 Smart Energy Forecast

Processing on behalf of the customer (Art. 28 GDPR).

Purpose: precise forecasts make it possible to optimise the use of the energy generated by small photovoltaic installations. With enercast SEF Smart Energy Forecast, output forecasts can be integrated into monitoring and energy-management systems with minimal effort via an efficient API.

On the basis of the technical data of the installation and weather forecasts from the world’s leading weather models, enercast SEF calculates the PV generation expected over the coming hours and days.

Recipient(s): enercast GmbH, Universitätsplatz 12, 34127 Kassel

Data processed: location data (e.g. GPS coordinates, geographical position of the PV installation, in so far as conclusions about the personal charging location are possible)

Legal basis: Art. 6(1)(b) GDPR; processing is carried out on behalf of the customer (Art. 28 GDPR)

Storage period: For the duration of the use of the service

 
4.1.6 Collection of company and infrastructure information

reev as controller in relation to the customer/administrator.

Purpose: correct configuration and personalisation of the platform (e.g. energy management, multi-account), ensuring consistent data management with the internal CRM, context-related improvement of support.

Recipient(s): salesforce.com Germany GmbH, Erika-Mann-Str. 31, 80636 München

Data processed:

  • information about the company and the users’ position
  • information about the company/fleet size and group affiliation
  • information about the technical infrastructure (e.g. PV installation, battery storage, smart meter, dynamic electricity tariff, electricity price, multi-account setup)

 

Legal basis: Art. 6(1)(b) GDPR (contract initiation/performance); Art. 6(1)(f) GDPR (legitimate interest in a functional and personalised platform).

Storage period: For the duration of the contractual relationship; upon termination of the contract, erasure in accordance with internal policies.

 
4.1.7 Support

Processing on behalf – Intercom is a sub-processor

Purpose: provision of a live-chat and customer-support widget for communication with website visitors and users, including the management of support requests, onboarding communication and the analysis of user behaviour to improve support

Recipient:Intercom R&D Unlimited Company, 124 St. Stephen’s Green, Dublin 2, DC02 C628, Ireland

Data processed:

  • contact and registration data (e.g. name, email address)
  • device data (e.g. operating system, browser type, IP address)
  • usage and session data (e.g. pages visited, session duration)
  • communication data (e.g. chat histories, support messages)
  • technical identifiers (e.g. cookie IDs, unique device IDs)

 

Legal basis: performance of the contract pursuant to Art. 6(1)(b) GDPR, in so far as the use of the support tool is necessary to provide the contractually agreed service; otherwise legitimate interest pursuant to Art. 6(1)(f) GDPR (optimisation of customer support and product quality); Cookies are set on the basis of Section 25(2) no. 2 TDDDG, as these cookies are technically necessary in order to provide the service expressly requested by you.

Storage period: For as long as the contract with Intercom exists; upon termination of the contract, active data are automatically erased after 180 days. On request, erasure takes place within 30 days

Additional information: Intercom uses the following cookies: “intercom-session-[app_id]”; “intercom-device-id-[app_id]”; “intercom-id-[app_id]”

 
4.1.8 Product and usage analysis

Processing on behalf – PostHog and Sentry are sub-processors; the product analysis serves the maintenance and further development of the platform within the scope of the customer’s instructions.

Purpose: analysis of the use of the reev Energy Hub (e.g. page views, click paths, feature usage) for the continuous improvement, error correction and further development of the platform.

Recipient(s): PostHog Inc., 2261 Market St., #4008, San Francisco, CA 94114, USA (servers in Frankfurt, Germany); Functional Software, Inc. (“Sentry”), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA (servers in Frankfurt, Germany)

Data processed:

  • Browser/operating system information, referrer URL, timestamp
  • Error and log data (stack traces, error messages) – Sentry
  • Pseudonymous usage data (page views, clicks, behavior) – PostHog
  • IP address (anonymized/truncated)

 

Legal basis: Article 6(1)(f) of the GDPR (quality assurance and further development).

Storage period: Sentry: no more than 90 days; PostHog: erasure/anonymisation once the purpose has been achieved.

Transfer to a third country: processing on EU servers; both providers are certified under the EU-US Data Privacy Framework.

 
4.1.9 Disclosure to installation and service partners

Processing on behalf; disclosure is carried out on behalf of the customer.

Purpose: arrangement and performance of installation, maintenance and support services on behalf of the customer, including error analysis and commissioning via digital tools (e.g. “reev Companion”).

Recipient(s): qualified electricians and installation/service partners acting on behalf of the customer

Data processed:

  • contact and address data of the installation site
  • technical information on the charging infrastructure, error messages
  • relevant contact information

 

Legal basis: Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR (efficient operation and support).

Storage period: For the duration of the respective service operation; thereafter erasure in accordance with the data processing agreement or retention periods.

 
4.2 reev Living

reev Living is reev’s digital charging service for residents of multi-family buildings, homeowners’ associations, residential complexes and comparable properties. reev provides end users with app-based access to the charging equipment present at the property, the authorisation of charging sessions as well as billing. The installation, technical operation and maintenance of the charging equipment are not part of the charging service – these are the responsibility of the respective owner or technical operator.

reev is itself the controller within the meaning of Art. 4(7) GDPR for the personal data of end users arising within the scope of the charging service.

 
4.2.1 Performance of the charging service

Purpose: creation and management of the user account, identification of the end user at the charging equipment, authorisation and recording of charging sessions as well as the creation and processing of invoices.

Recipient(s): Stripe Payments Europe, Limited, Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (payment service provider, including 3D Secure 2.0).

Data processed:

  • master and contact data (first and last name, billing address, email address, optionally telephone number)
  • login and authentication data (email, password, session data)
  • assigned authorisations (e.g. residential unit, parking space, charging group, RFID tag/charge card, app access)
  • data on the charging session (charge point, start/end, energy charged, status, tariff)
  • payment data (IBAN, credit card data – transmitted in encrypted form)
  • invoice data (invoice amount, taxes, invoice date, charging sessions billed)

 

Legal basis: Art. 6(1)(b) GDPR (performance of the contract); Art. 6(1)(c) GDPR in conjunction with PSD2/ZAG (strong customer authentication) as well as in conjunction with commercial and tax-law retention obligations; Art. 6(1)(f) GDPR (secure authentication and prevention of misuse).

Storage period: For the duration of the active usage relationship; invoice and payment data in accordance with statutory retention periods (as a rule, 10 years). Other data are erased after termination of the contract within the customary period.

 
4.2.2 Processing of meter and metering data

Purpose: determination of the quantity of electricity drawn via the charging-infrastructure meter for the billing of charging sessions as well as for the plausibility check of total consumption vis-à-vis both reev and the property manager. The processing is carried out exclusively in the case of analogue meters or intelligent metering systems (iMSys); meters with registering load metering (RLM) are excluded.

Recipient(s): the competent grid operator and metering point operator (for legitimation and data exchange under energy-industry law); Amazon Web Services EMEA SARL (server infrastructure).

Data processed:

  • meter number and market/metering location
  • meter readings (manual readings or automated iMSys values; in the case of iMSys, up to quarter-hourly measured values)
  • consumption data of the charging equipment, allocation to charge points and residential units

 

Legal basis: Art. 6(1)(b) GDPR (performance of the contract); Art. 6(1)(c) GDPR (energy-law/metering-point-law obligations); Art. 6(1)(f) GDPR (plausibility check of total consumption, prevention of misuse).

Storage period: For the duration of the contractual relationship as well as in accordance with statutory retention periods.

 
4.2.3 Contact details of the contact person of the property manager

Purpose: performance and handling of the permission and site agreement with the property manager (e.g. clarification of property-related questions, communication of meter readings, information about authorised users, coordination of service operations / repairs).

Data processed:

  • first and last name of the contact person
  • function/role
  • business telephone number and email address

 

Legal basis: Article 6(1)(b) of the GDPR (performance of the agreement)

Storage period: For the duration of the agreement with the property manager; thereafter erasure in accordance with internal policies or statutory retention periods

 
4.2.4 Product and usage analysis

Purpose: analysis of usage (e.g. page views, click paths, feature usage) for the continuous improvement, error correction and further development of the platform.

Recipient(s): PostHog Inc., 2261 Market St., #4008, San Francisco, CA 94114, USA (servers in Frankfurt, Germany); Functional Software, Inc. (“Sentry”), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA (servers in Frankfurt, Germany)

Data processed:

  • Browser/operating system information, referrer URL, timestamp
  • Error and log data (stack traces, error messages) – Sentry
  • Pseudonymous usage data (page views, clicks, behavior) – PostHog
  • IP address (anonymized/truncated)

 

Legal basis: Article 6(1)(f) of the GDPR (quality assurance and further development).

Storage period: Sentry: no more than 90 days; PostHog: erasure/anonymisation once the purpose has been achieved.

Transfer to a third country: processing on EU servers; both providers are certified under the EU-US Data Privacy Framework.

 
4.3 reev App

The reev App enables drivers, among other things, to activate and control charging sessions, to manage charge cards and tariffs as well as to handle billing. Depending on the usage context (see Section 1), reev is either the customer’s processor or itself the controller.

 
4.3.1 Provision and download of the App

Purpose: provision of the mobile app on the user’s terminal device

Recipient(s): Apple Inc. (App Store) or Google Ireland Ltd. (Google Play) – as separate controllers

Data processed:

  • App Store data (user name, customer number, email address, download time, payment information)
  • device/identification data (e.g. unique device number, operating system)
  • usage data (IP address, date/time of the request)

 

Legal basis: Art. 6(1)(b) GDPR (performance of the contract); Art. 6(1)(f) GDPR (security/operation of the App).

Storage period: For the duration of the use of the App as well as in accordance with statutory retention periods.

4.3.2 Registration and login

Purpose: creation and management of the user account, authentication in the App.

Data processed:

  • login data (email address, password)
  • profile information (first and last name)
  • authentication data (IP address, login times, session ID, device type)

 

Legal basis: Art. 6(1)(b) GDPR (performance of the contract); Art. 6(1)(f) GDPR (secure authentication).

Storage period: For the duration of the active user account; following erasure, subsequent removal within the customary period.

 
4.3.3 Functions of the App – management of charging sessions and payment

Purpose: activation and control of charging sessions, management of tariffs and charge cards, provision of the monthly billing statement.

Recipient(s): Stripe Payments Europe, Limited, Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (for payments arising from charging sessions, including 3D Secure 2.0)

Data processed:

  • address data (street, house number, postcode, town, country)
  • credit card data (encrypted, transmitted to the payment service provider)
  • data on the charging session (station, start/end, energy charged, tariff, invoice amount)

 

Legal basis: Art. 6(1)(b) GDPR (performance of the contract); Art. 6(1)(c) GDPR in conjunction with PSD2/ZAG (strong customer authentication).

Storage period: For the duration of the contractual relationship as well as in accordance with statutory retention periods (in particular under commercial and tax law).

Further information: https://stripe.com/de/privacy

 
4.3.4 Vehicle connectivity

Purpose: establishment and maintenance of a connection to the vehicle, retrieval of vehicle data within the App.

Recipient(s): Smartcar, Inc., 650 Castro St STE 120-99699, Mountain View, CA 94041, USA

Data processed:

  • vehicle identifiers (e.g. vehicle identification number)
  • connection/authentication data
  • vehicle and usage data (e.g. vehicle status, telemetry data) – depending on the authorisations granted

 

Legal basis: Art. 6(1)(a) GDPR (consent; withdrawal possible at any time by disconnecting the vehicle in the App).

Storage period: Until withdrawal of consent or disconnection of the vehicle.

Transfer to a third country: transfer to the USA on the basis of EU standard contractual clauses (Art. 46 GDPR).

 
4.3.5 Special function “Charging a company car at home”

Hybrid constellation: reev is the employer’s processor; the reimbursement relationship exists between the user and the employer

Purpose: registration of the private charging station for charging the company vehicle and automated transmission of the billing-relevant data to the employer for cost reimbursement.

Recipient(s): the respective employer/customer

Data processed:

  • tariff information of the private electricity connection (electricity price, time-based rates)
  • data on charging sessions at the private charging station (charging duration, energy charged, stored price)
  •  

Legal basis: Art. 6(1)(b) GDPR (performance of the usage relationship between reev and the user); Art. 28 GDPR in relation to the employer

Storage period: For the duration of the registration of the private charging station or of the company-car programme

 
4.3.6 Error monitoring (Sentry)

Purpose: automated logging and diagnosis of App errors to ensure the stability and quality of the App

Recipient(s): Functional Software, Inc. (“Sentry”), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA (servers in Frankfurt, Germany)

Data processed:

  • name and version of the browser/terminal device used, operating system
  • referrer URL, time of the server request
  • error and log data (stack traces, error messages)

 

Legal basis: Art. 6(1)(f) GDPR (quality assurance and error correction)

Storage period: After no more than 90 days or in accordance with the contractual agreement

Transfer to a third country: processing on EU servers; Sentry is certified under the EU-US Data Privacy Framework. The IP address is anonymised via Sentry

Further information: https://sentry.io/privacy/

 
4.3.7 Diagnostic/crash data (Microsoft App Center)

Purpose: analysis of usage as well as crash and performance diagnosis of the App

Recipient(s): Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland

Data processed: anonymised diagnostic data (crash tracesnumber of app launchesrestarts) 

Legal basis: Art. 6(1)(f) GDPR (secure operation of the App)

Storage period: In accordance with the requirements of Microsoft App Center; erasure once the purpose has been achieved

 
4.3.8 Product and usage analysis

Processing on behalf – PostHog and Sentry are sub-processors and support the maintenance and further development of the App.

Purpose: analysis of App usage for continuous improvement, error analysis and further development

Recipient(s): PostHog Inc., 2261 Market St., #4008, San Francisco, CA 94114, USA (servers in Frankfurt, Germany); Functional Software, Inc. (“Sentry”), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA (servers in Frankfurt, Germany)

Data processed:

  • Browser/operating system information, referrer URL, timestamp
  • Error and log data (stack traces, error messages) – Sentry
  • Pseudonymous usage data (page views, clicks, behavior) – PostHog
  • IP address (anonymized/truncated)

 

Legal basis: Art. 6(1)(f) GDPR (quality assurance and further development); processing within the scope of the customer’s instructions pursuant to Art. 28 GDPR or, in relation to the App user, on the basis of legitimate interests

Storage period: Sentry: no more than 90 days; PostHog: erasure/anonymisation once the purpose has been achieved.

Transfer to a third country: processing on EU servers; both providers are certified under the EU-US Data Privacy Framework.

 
4.3.9 System permissions

Certain functions of our App require access to specific interfaces and data on your device. Depending on the operating system, your express consent is required for this. You can manage and withdraw the permissions at any time in the system settings of your device.

  • Location Services – for location-based display of charging stations
  • Push notifications – for status updates on charging sessions
  • Bluetooth – for connecting to Bluetooth-enabled devices/charging stations
  • Camera – e.g., for scanning QR codes at charging stations
  • Mobile data/network connections – for data transmission to our servers
  • Access to device storage – limited to the app-specific area

 

4.4 reev.one (Web Portal)

reev.one is the web portal for drivers/end users with a largely similar range of functions to the reev App. The controllership role is determined in accordance with Section 1.

4.4.1 Provision of and access to the web portal

Purpose: provision of the reev.one web portal and ensuring a smooth connection setup.

Data processed:

  • Date and time of access
  • Name and URL of the file accessed
  • Browser used and, if applicable, operating system; name of the Internet service provider
  • IP address (deleted after 7 days at the latest or pseudonymized)

 

Legal basis: Article 6(1)(f) of the GDPR (ensuring stability, security, and error analysis).

Storage period: IP address for a maximum of 7 days, thereafter erasure or pseudonymisation.

 
4.4.2 Cookies

Purpose: provision of the functionality of the web portal (session, consent, server stability)
Recipient(s): storage on the user’s terminal device; no transmission to third parties.
Data processed:

  • IP address
  • Session ID
  • Authentication status (e.g., login status “logged in/logged out,” user role flag)

 

Legal basis: Art. 6(1)(f) GDPR, Section 25(2) TDDDG (ensuring functions).

Storage duration: Until the end of the session or according to the individual cookie’s lifetime.

 
4.4.3 Payment processing of charging sessions

Purpose: processing of payments for charging sessions carried out.

Recipient(s): Stripe Payments Europe, Limited, Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland

Data processed:

  • email address and further data required for invoice processing
  • information on the charging session (location, invoice amount, taxes)

 

Legal basis: Art . 6(1)(b) of the GDPR (performance of a contract); Art. 6(1)(f) of the GDPR (user-friendly payment processing).

Storage period: For the duration of the contractual relationship as well as in accordance with statutory retention periods.

 
4.4.4 Error monitoring and product analysis

Purpose: error analysis and analysis of usage for the continuous improvement of the web portal.

Recipient(s): Functional Software, Inc. (“Sentry”), 45 Fremont Street, San Francisco, CA 94105, USA; PostHog Inc., 2261 Market St., #4008, San Francisco, CA 94114, USA – servers in each case in Frankfurt, Germany.

Data processed:

  • Browser/operating system information, referrer URL, timestamp
  • Error and log data (stack traces, error messages) – Sentry
  • Pseudonymous usage data (page views, clicks, behavior) – PostHog
  • IP address (anonymized/truncated)

 

Legal basis: Article 6(1)(f) of the GDPR (quality assurance and further development).

Storage period: Sentry: no more than 90 days; PostHog: erasure/anonymisation once the purpose has been achieved.

Transfer to a third country: processing on EU servers; both providers are certified under the EU-US Data Privacy Framework.

 
4.5 reev Payment Terminal

Via the reev Payment Terminal, ad-hoc drivers can charge by debit or credit card directly at the charging station without having to create a user account with reev. In relation to the ad-hoc driver, reev is itself the controller for the payment processing arising in this context.

 
4.5.1 Use of the user interface and payment processing

Purpose: reading of the payment card data to check authorisation and to handle payment for the charging session.

Recipient(s): Payter BV, Rozenlaan 115, 3051 LP Rotterdam, the Netherlands (payment-terminal backend); ELAVON Financial Services DAC, German Branch, Lyoner Str. 36, 60528 Frankfurt/Main (payment service provider, separate controller pursuant to the GDPR).

Data processed:

  • Card Number (PAN)
  • Date and Time
  • Amount Charged
  • Last Name and First Name (for ELAVON processing)
  • Credit card or account information (depending on the selected payment method)
  • Invoice amount, payment date
  • Information about the charging station used
  • Email address (optional, if a receipt is requested)

 

Legal basis: Art. 6(1)(b) GDPR (performance of the contract); Art. 6(1)(c) GDPR in conjunction with PSD2/ZAG (strong customer authentication); Art. 6(1)(f) GDPR (user-friendly payment processing).

Storage period: Storage by ELAVON for the handling of the payment and to comply with statutory retention obligations.

 
4.6 reev Companion (electrician tool)

reev Companion is an onboarding and commissioning tool for electricians. For the electrician’s account data, reev is itself the controller; for the end-customer data transmitted within the scope of onboarding, reev is the respective customer’s processor.

 
4.6.1 Collection and transmission of onboarding and installation data

Purpose: support of the electrician in the commissioning of the charging infrastructure and the energy management, creation of the electrician account as well as collection and storage of the onboarding and installation data required for commissioning

Data processed:

  • email address of the electrician / installer (for account creation and communication within the scope of commissioning)
  • email address and, where applicable, further contact data of the customer / end customer
  • location data of the installation (address, town, where applicable precise location designation such as underground parking space, residential unit)
  • information on the installed charging station (e.g. manufacturer, model, serial number, number of charge points, technical configuration, connection type)
  • information on the activated energy management (e.g. grid connection capacity, topology, energy meter)
  • commissioning and status information

 

Legal basis: Art. 6(1)(b) GDPR (performance of the contract with the electrician for account creation and commissioning communication)

Storage period: For the duration of the active electrician account or of the respective commissioning/service operation. End-customer and installation data are erased in accordance with the data processing agreement with the customer; statutory retention periods (e.g. under commercial and tax law) remain unaffected.

 
4.6.2 Usage analysis

Purpose: analysis of App usage to improve the tool

Recipient(s): PostHog Inc., 2261 Market Street, Suite 4008, San Francisco, CA 94114 (servers in Frankfurt, Germany); Functional Software, Inc. (“Sentry”), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA (servers in Frankfurt, Germany)

Data processed:

  • Browser/operating system information, referrer URL, timestamp
  • Error and log data (stack traces, error messages) – Sentry
  • Pseudonymous usage data (page views, clicks, behavior) – PostHog
  • IP address (anonymized/truncated)

 

Legal basis: Article 6(1)(f) of the GDPR (quality assurance and further development).

Storage period: Sentry: no more than 90 days; PostHog: erasure/anonymisation once the purpose has been achieved.

Transfer to a third country: processing on EU servers; both providers are certified under the EU-US Data Privacy Framework.

Further information: Following consent given via the consent banner, a technically non-essential cookie is set by PostHog (“ph_phc_[ID]”).

 
4.6.2 Support

Purpose: provision of a live-chat and customer-support widget for communication with website visitors and users, including the management of support requests, onboarding communication and the analysis of user behaviour to improve support

Recipient:Intercom R&D Unlimited Company, 124 St. Stephen’s Green, Dublin 2, DC02 C628, Ireland

Data processed:

  • Contact and registration information (e.g., name, email address)
  • Device data (e.g., operating system, browser type, IP address)
  • Usage and session data (e.g., pages visited, session duration)
  • Communication data (e.g., chat histories, support messages)
  • Technical identifiers (e.g., cookie IDs, unique device IDs)

 

Legal basis: performance of the contract pursuant to Art. 6(1)(b) GDPR, in so far as the use of the support tool is necessary to provide the contractually agreed service; otherwise legitimate interest pursuant to Art. 6(1)(f) GDPR (optimisation of customer support and product quality); Cookies are set in accordance with Section 25(2)(2) of the TDDDG, as these cookies are technically necessary to provide the service you have expressly requested.

Storage period: For as long as the contract with Intercom exists; upon termination of the contract, active data are automatically erased after 180 days. On request, erasure takes place within 30 days

Additional information: Intercom uses the following cookies: “intercom-session-[app_id]”; “intercom-device-id-[app_id]”; “intercom-id-[app_id]”

 
4.6.3 Transmission to service/installation partners

Processing on behalf of the customer.

Purpose: transmission of installation, maintenance and support information between reev and authorised installation/service partners.

Recipient(s): authorised installation and service partners of the customer

Data processed:

  • Technical Information on the Charging Infrastructure and Error Messages
  • Contact information for the end customer/installation site

 

Legal basis: Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR (efficient operation and support).

Storage period: For the duration of the respective service operation.

 
4.7 reev Companion Plus (partner portal for hardware manufacturers and full-service providers)

Via reev Companion Plus (formerly Partner Portal), hardware manufacturers (charging-station OEMs) as well as full-service providers obtain read access to monitoring, analysis and support functions for the charging stations they manufacture and which are connected to reev. In this respect, reev is the respective customer’s processor; the partner acts on the basis of the data processing agreement between reev and the customer.

4.7.1 Monitoring and support of the charging stations

Processing on behalf of the customer (Art. 28 GDPR).

Purpose: monitoring of operability, error analysis and maintenance of the charging stations manufactured by the partner

Recipient(s): the respective hardware manufacturer / partner

Data processed:

  • Charging station, customer, and location data (customer name, location name, charging group name, technical configuration)
  • Error messages, telemetry data from the charging station

 

Legal basis: Article 6(1)(f) of the GDPR (legitimate interest of reev and its customers in ensuring the proper functioning of the hardware)

Storage period: For the duration of the contractual relationship between reev and the customer or for as long as required for support

 
4.8 reev Stromtarif (cooperation with Nomos GmbH)

For the “reev Stromtarif” feature, reev cooperates with Nomos GmbH (“Nomos”). reev and Nomos are joint controllers within the meaning of Art. 26 GDPR. An agreement on joint controllership has been concluded.

Allocation of tasks:

  • Nomos: conclusion and performance of the energy supply contract, change of supplier, billing within the supply relationship as well as associated legal obligations.
  • reev: operation of the platform, setting up and management of the customer account (portal/app), technical and specialist support, visualisation of consumption data.
4.8.1 Energy supply contract and consumption metering

Joint controllership reev / Nomos (Art. 26 GDPR).

Purpose: conclusion and performance of the energy supply contract, change of supplier, billing and visualisation of consumption data

Recipient(s): Nomos GmbH; market partners involved in the energy supply (in particular grid and metering point operators); payment service providers and banks; IT/hosting/support/cloud service providers (as processors); tax advisers/auditors and authorities, where legally required

Data processed:

  • First and last name, email address, shipping address
  • Meter type and meter number, estimated annual consumption, reason for switching
  • Bank account information (account holder, IBAN)
  • Name of the previous utility provider, name of the grid/metering point operator
  • Market and metering location
  • Electricity consumption data (for smart metering systems, up to quarter-hourly readings)
  • For reev, additionally: contract status, start/end of supply, monthly consumption figures

 

Legal basis: Art. 6(1)(b) GDPR (performance of the contract and pre-contractual measures); Art. 6(1)(c) GDPR (legal obligations, in particular commercial/tax-law retention obligations, EnWG); Art. 6(1)(f) GDPR (IT and platform security, prevention of misuse and fraud)

Storage period: For the duration of the contractual relationship as well as in accordance with statutory retention periods

Transfer to a third country: processing in principle within the EU/EEA; in the event of transfer to third countries, reev and/or Nomos ensure that either an adequacy decision or appropriate safeguards pursuant to Art. 44 et seq. GDPR are in place

For more information: Nomos Privacy Policy : https://www.nomos.energy/privacy

Data subjects may exercise their rights under the GDPR against either of the two controllers. We recommend contacting the respective primary point of contact – reev via privacy(at)reev.com or Nomos via the contact details set out in their data protection information.

 

5. Contacting us

If you contact us by email or via other channels of communication, we process the personal data you provide (e.g. name, email address, content of the message) solely for the purpose of handling and responding to your enquiry. The legal basis is, as a rule, our legitimate interest in communicating with you (Art. 6(1)(f) GDPR) or – in so far as the enquiry serves the initiation or performance of a contract – Art. 6(1)(b) GDPR. Your data are stored only for as long as is necessary to handle your enquiry. No disclosure to third parties takes place unless we are legally obliged to do so or this is indispensable for handling your enquiry.

 

6. International data transfers

We process your data in principle within the EU and the EEA. However, some service providers are located in so-called “third countries”. The GDPR imposes high requirements in this respect. All recipients must meet these requirements. Before transferring data to a third-country service provider, we examine the level of data protection and select only providers with demonstrably adequate protection. Every processor – including those outside the EEA – has concluded a data processing agreement with us. Additional requirements apply to providers outside the EEA: pursuant to Art. 44 et seq. GDPR, data may be transferred if at least one of the following conditions is met:

  • The EU Commission has determined that there is an adequate level of data protection (e.g. the EU-US Data Privacy Framework).
  • Standard contractual clauses have been agreed with the recipient.
  • Other appropriate safeguards pursuant to Art. 46 GDPR.
  • In exceptional cases, one of the derogations under Art. 49 GDPR applies.

 

7. Recipients of data

As a rule, a transfer of the personal data we collect takes place only where:

  • you have given your express consent pursuant to Art. 6(1)(a) GDPR,
  • the disclosure is necessary pursuant to Art. 6(1)(f) GDPR to safeguard legitimate interests or for the establishment, exercise or defence of legal claims, and there is no reason to assume that your interests warranting protection override these,
  • we are legally obliged to do so (Art. 6(1)(c) GDPR), or
  • the disclosure is necessary for the performance of a contract or for the performance of pre-contractual measures (Art. 6(1)(b) GDPR).

 

Possible recipients are:

  • Processors: external service providers, e.g. in the area of technical infrastructure, maintenance, support, product and usage analysis or payment processing. These may use data exclusively in accordance with our instructions.
  • Separate controllers: in particular payment service providers within the scope of their legal obligations (e.g. ELAVON, card-issuing banks, acquirers).
  • Joint controllers: Nomos GmbH within the scope of the “reev Stromtarif” feature.
  • Public bodies: authorities and public offices (e.g. tax authorities, public prosecutors’ offices, courts), in so far as we are legally obliged to do so or legitimate interests so require.

 

8. Data security and protective measures

We ensure that your personal data remain secure and confidential. To protect against manipulation, loss or misuse, we employ technical and organisational measures which are regularly reviewed and adapted to the state of the art.

Please note that other persons or institutions on the internet may disregard data protection requirements. In particular, unencrypted data (e.g. emails) may be viewed by third parties. We have no influence over this. You should therefore protect your data against misuse by means of encryption or comparable measures.

 

9. Data storage

Personal data are erased or blocked as soon as the purpose of storage ceases to apply. Storage may also take place where this is provided for by European or national legislation. Data are furthermore blocked or erased where a statutory retention period expires, unless they are still required for the performance of a contract.

 

10. Data subject rights

In respect of your personal data, you have the following rights:

  • Right of access (Art. 15 GDPR, Section 34 BDSG): You can request information as to whether and which personal data are processed by us, for what purpose, to which recipients or categories of recipients the data are transmitted and for how long the data are stored.
  • Right to rectification (Art. 16 GDPR): You can request the immediate rectification of inaccurate personal data or the completion of incomplete personal data.
  • Right to erasure (Art. 17 GDPR): You can request the erasure of your personal data, in particular where these are no longer necessary, where you withdraw your consent or where the data have been processed unlawfully.
  • Right to restriction of processing (Art. 18 GDPR): You can request the restriction of the processing of your data, e.g. where the accuracy of the data is contested.
  • Right to data portability (Art. 20 GDPR): You have the right to receive the personal data concerning you which you have provided to us in a structured, commonly used and machine-readable format or – in so far as technically feasible – to request the transmission to another controller.
  • Right to withdraw consent (Art. 7(3) GDPR): You can withdraw consent given at any time with effect for the future. The lawfulness of the processing carried out up to the withdrawal remains unaffected.
  • Right to object (Art. 21 GDPR): You can object at any time, on grounds relating to your particular situation, to the processing of your personal data, in particular in connection with direct marketing or related profiling.
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes data protection provisions.

 

11. Change History

Date

Version

Reason for Change

July 1, 2026

1.0

First consolidated version – replaces previous separate privacy policies

We are happy to support you!

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Name*
Requested hardware *