Privacy Policy for the HASE iQ app

We are pleased you have installed and are using the Hase iQ app (hereinafter: iQ app), and about your interest in the details of data processing by the data controller for the iQ app under data protection laws, HASE Kaminofenbau GmbH, Niederkircher Str. 14, 54294 Trier (hereinafter: HASE)

The protection of your personal data during use of the iQ app is an important concern to us. Personal data is information about personal or factual circumstances regarding an identified or identifiable natural person. This includes, for example, your legal name, address, phone number and date of birth, but also all other data which can be related to an identifiable person.

Since personal data enjoys special legal protection, we only collect this data to the extent necessary for provision of the iQ app and provision of our services. Below, we outline what personal information we collect when you use the iQ app and how we use it.

Our data protection practice is in accordance with the statutory provisions of the EU General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG), and the Telecommunications Digital Services Data Protection Act (TDDDG). We will only collect, process and store your personal data to the extent that is necessary to provide the iQ app, as well as our content and services, in functional form.

Data controller

The data controller within the meaning of the GDPR and other national data protection laws of the member states as well as other data protection regulations is

HASE Kaminofenbau GmbH
Niederkircher Straße 14
54294 Trier
Phone: +49 (0) 651 82 69-0
Fax: +49 (0) 651 82 69-118
E-Mail: info@hase.de
Website: www.hase.de

Contact details of the data protection officer

You can reach our data protection officer using the following contact details:

TÜV SÜD Akademie GmbH 
Westendstraße 160 
80339 München 
E-Mail: datenschutz@hase.de

You can contact our data protection officer directly at any time if you have any questions or suggestions regarding our data protection practices or this Privacy Policy.


Hosted by Google Cloud EMEA

We host our database at Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland. If you use our app, your personal data (e.g., IP addresses in log files) will be processed on Google's servers. These processing operations are carried out exclusively in the event that express consent is granted in accordance with Art. 6 (1) (a) GDPR. The further use of Google is based on Art. 6 (1) (f) GDPR. We have a legitimate interest in the most reliable presentation, provision, and protection of our app.

The parent company Google LLC is certified as a US company under the EU-US Data Privacy Framework. An adequacy decision per Art. 45 GDPR is thus in place, meaning that a transfer of personal data may also take place without further guarantees or additional measures.

Further information on data protection can be found in Google's privacy policy: https://policies.google.com/privacy.


iQ app setup process

When you set up your furnace, the app will query a list of existing Wi-Fi networks and check whether access points of HASE furnaces are among them. As soon as the app is connected to your furnace via the access point, it will receive a list of available Wi-Fi networks from the furnace. You select one of them and enter the password for it in the app. This is then transmitted to the furnace and used by the furnace to establish a connection to the Wi-Fi.

Purpose of data processing

The app uses the surrounding Wi-Fi networks to automatically connect to the access point of the nearby furnace. This data is used exclusively locally. The SSID and password of your Wi-Fi will be transmitted to the furnace in order to connect the furnace to it. The password is transmitted in encrypted form.

Legal basis for the processing of personal data

The processing is necessary for the fulfilment of the contract for use of the app (Art. 6 (1) (b) GDPR). Without the processing of the above-mentioned data on the end device, use of the iQ app is not possible.

Duration of storage

The data will be removed from your device after use of the iQ app. The Wi-Fi data will be stored on your furnace for an indefinite period of time. You can overwrite the Wi-Fi data or delete it by resetting the furnace.


Basic iQ app functionality

When you use the iQ app, information about your furnace, specifically the model, the serial number of the furnace, the serial number of the iQ controller, the name, the brightness of the LEDs, the availability of updates, the IP address of your furnace or furnaces, is transmitted from the furnace to a HASE server and processed and stored there. While your furnace is burning, as well as at the end of each firing process, firing data from your furnace or furnaces (specifically: the time, temperature, performance, firing phase, firing duration, replenishment status, replenishment time and error codes) are also transmitted to the HASE server, and are processed and stored there.

Your device accesses this data via the iQ app.

Purpose of data processing

The data is transmitted to your device and processed there to visualise the current and past burning processes within the iQ app. In addition, push notifications are sent for refilling fuel and if errors occur. Furthermore, the long-term development of the combustion values is displayed in the app to provide you with a detailed overview of the performance of your furnace.

If you have explicitly consented to the use of data by HASE, HASE will also be able to view combustion logs in order to use them for product improvement and remote maintenance. In the event of subsequent approval, historical data can be viewed.

Legal basis for the processing of personal data

The processing is necessary to fulfil the contract for use of the app in accordance with Art. 6 (1) (b) GDPR is required The legal basis for the data processing is also Art. 6 (1) (a) GDPR. The processing of your personal data is based on your previously given consent. This consent can be revoked at any time.

Duration of storage

The data is stored for an indefinite period of time. You can delete the combustion data of your furnace at any time via the app. If you resell your furnace, we recommend that you delete your combustion data in this way.


Checking for firmware updates

When the iQ app is used, the up-to-dateness of the firmware of the furnaces used is checked, and any new firmware is pointed out in the app. In the course of this query, the IP address of your mobile device and other information about the device and the transmission itself (as part of the protocol-based communication over the Internet), as well as the current status of the firmware of your furnace or furnaces, are transmitted to a HASE server.

Purpose of data processing

The transmission of data is used to check firmware updates for your furnace or furnaces.

 

Legal basis for the processing of personal data

The processing takes place on the basis of legitimate interest in accordance with Art. 6 (1) (f) GDPR. Our legitimate interest lies in ensuring that the furnaces function properly, which is ensured by regular updates.

 

Duration of storage

The data is deleted on the server immediately after transfer of the information to the firmware.

 


Data security and privacy, communication by email

Your personal data is protected by technical and organisational measures during collection, storage and processing in such a way that its are not accessible to third parties. Nevertheless, internet-based data transmission can have security gaps, and absolute protection cannot be guaranteed. In the case of unencrypted e-mail communication, we cannot guarantee complete data security en route to our IT systems, so we recommend encrypted communication or postal mail for information requiring a high degree of confidentiality.

 

Use of your data for product improvement and remote maintenance

We use your personal data to improve our products and to carry out remote maintenance services in accordance with Art. 6 (1) (a) GDPR on the basis of your express consent. You can give this consent during the setup process in the Hase iQ app by agreeing to our company having viewing rights. Your consent enables us to respond to potential problems in a targeted manner and to continuously optimise our products.

The data collected from you will only be stored for as long as is necessary for the stated purposes or until you revoke your consent. After the purpose has been achieved, or if your consent is revoked, the data will be deleted immediately, unless there are legal retention obligations.

Your rights as a data subject

Right to confirmation

You have the right to request confirmation from us as to whether we are processing personal data relating to you.

Right of access, Art. 15 GDPR

You have the right to receive free information from us about the personal data stored about you, as well as a copy of this data, at any time, in accordance with the legal provisions.

Right to rectification, Art. 16 GDPR

You have the right to request the rectification of inaccurate personal data relating to you. Furthermore, taking into account the purposes of the processing, you have the right to request that incomplete personal data be completed.

Right to erasure, Art. 17 GDPR

You have the right to demand from us that the personal data concerning you be deleted without delay, provided that one of the reasons provided by law is met and the processing or storage is not required.

Right to restriction of processing, Art. 18 GDPR

You have the right to request that we restrict processing if one of the legal conditions is met.

Right to data portability, Art. 20 GDPR

You have the right to obtain the personal data of yours that you have provided to the data controller in a structured, commonly used, and machine-readable format. You also have the right to transfer this data to another data controller, without obstruction on the part of us, to whom the personal data was provided, provided that the processing is based on consent per Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract per Art. 6 (1) (b) GDPR and the processing is carried out by means of automated procedures, except where such processing is necessary for the performance of a task in the public interest or in the exercise of official authority conferred on us.

Furthermore, when exercising your right to data portability pursuant to Art. 20 (1) GDPR, you have the right to have personal data transmitted directly from one data controller to another data controller, insofar as this is technically feasible and this does not affect the rights and freedoms of other persons.

Right to object, Art. 21 GDPR

You have the right to object, at any time, for reasons arising from your particular situation, to the processing of your personal data carried out on the basis of Art. 6 (1) (e) (data processing in the public interest) or (f) (data processing based on a balance of interests) of the GDPR.

Right to lodge a complaint with a supervisory authority

You have the right to complain to a data protection supervisory authority about our processing of personal data. A list of supervisory authorities (for the non-public sector) and their addresses can be found at: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.

Updates to this Privacy Policy

We reserve the right to adapt this Privacy Policy to technical developments or to update it in connection with new product offers if necessary. Likewise, updates take place as a result of legal requirements.