Legal
How we handle your personal data
This policy explains what personal data ChargeControl B.V. processes, why, and the rights you have as a data subject under the GDPR.
Overview
ChargeControl B.V. (“we”, “us”, “our”) respects your privacy and is committed to protecting your personal data. This privacy policy informs you about how we handle your personal data.
Data Controller
ChargeControl B.V. is responsible for processing your personal data as described in this privacy policy. We are based in Rotterdam, Netherlands and operate in accordance with the General Data Protection Regulation (GDPR).
Data We Collect
2.1 Directly Provided Data
- Identity data: name, email address, phone number
- Business data: company name, job title, registration number
- Vehicle data: license plate, make/model, battery capacity
- Charging data: session information, location, consumption
- Financial data: bank account for reimbursements
2.2 Automatically Collected Data
- Device and browser information
- IP address and location data (with consent)
- Usage patterns and interactions with our services
- Smart meter data (P1 dongle, with consent)
- Energy market data (EPEX Spot prices, grid tariffs)
- AI-processed operational data (anonymized for model improvement)
2.3 Partner Portal Data
When using the Partner Portal, we collect and process additional data necessary for partner operations, including customer management, wizard configurations, installation pipelines, and AI-powered operational insights. This data is processed in accordance with your partner agreement.
Legal Basis for Processing
| Purpose | Legal Basis |
|---|---|
| Service delivery | Contract performance (Art. 6(1)(b)) |
| Reimbursement processing | Contract performance (Art. 6(1)(b)) |
| Tax reporting | Legal obligation (Art. 6(1)(c)) |
| Product improvement | Legitimate interest (Art. 6(1)(f)) |
| Marketing communications | Consent (Art. 6(1)(a)) |
Data Security
We implement appropriate technical and organizational measures to protect your personal data:
- End-to-end encryption for all data transmission (TLS 1.3)
- Blockchain-based session verification for integrity
- Role-based access control (RBAC)
- Regular security audits and penetration testing
- ISO 27001 certified datacenter in EU
Data Sharing
We only share your data with:
- Your employer (for reimbursement processing, anonymized totals only)
- Charging network operators (for session authorization)
- Payment processors (secure transaction processing)
- Energy market operators (for spot price optimization and VPP participation)
- Verified partners where sharing is required under the applicable partner agreement
- Government authorities (only when legally required)
Your Rights
Under GDPR, you have the following rights:
- Access — Request a copy of your personal data.
- Rectification — Correct inaccurate or incomplete data.
- Erasure — Request deletion (“right to be forgotten”).
- Restriction — Restrict processing of your data.
- Portability — Receive your data in a structured format.
- Objection — Object to processing based on legitimate interest.
Submit requests to privacy@chargecontrol.ai. We respond within 30 days.
Retention Periods
| Data Type | Retention Period |
|---|---|
| Account data | Up to 2 years after account deletion |
| Charging sessions | 7 years (tax requirements) |
| Reimbursement records | 7 years (tax requirements) |
| Marketing preferences | Until consent withdrawal |
International Transfers
Your data is stored and processed within the European Economic Area (EEA). For transfers outside the EEA, we ensure appropriate safeguards such as Standard Contractual Clauses (SCC).
Complaints
You have the right to file a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl) if you believe your data is not being processed correctly.
Privacy Contact
ChargeControl B.V.
Stationsplein 45
3013 AK Rotterdam
The Netherlands
KvK: 42006134
Data Protection Officer (DPO) available upon request.