Global Commitment to Privacy

EKO Instruments is committed to protecting your personal data. We abide by all applicable laws and regulations, with a particular focus on the EU General Data Protection Regulation (GDPR) as our global standard for data privacy. We may update this Privacy & Data Protection Policy from time to time to reflect changes in our practices or legal requirements. Any changes will be posted on this page, and where appropriate, notified to you. This policy is effective from April 12, 2025.

Introduction

EKO-Q is a web-based software-as-a-service (SaaS) platform provided by EKO Instruments for both business (B2B) and individual (B2C) users. This Privacy Policy explains what types of information we collect through the EKO-Q application, how we use and protect that information, and the rights you have in relation to your personal data. It applies when you access EKO-Q , its Application Programming Interface(s) or any other interface related to it (related apps, marketing dashboard, analytical dashboards, etc.). Protecting your privacy and personal information is one of our top priorities. If you have any questions about this Policy or how EKO Instruments handles your data, please contact us using the details in the Contact section below.

Types of Data We Collect

When you use EKO-Q, we collect several types of data to provide and improve our services. We only collect data that is necessary for the purposes described in this Policy. The types of data we collect include:

  • Account Information: When you register an account, we collect personal identifiers such as your name and email address. If you register on behalf of a business, we may also collect your company name, company address, industry, and VAT ID (for billing and tax purposes). You will also create login credentials (such as a password) to secure your account.
  • Contact and Profile Details: You may provide additional contact information like a phone number or job title, and other profile details at your discretion. These details help us communicate with you and personalize your experience.
  • Payment Information: If you purchase a subscription or paid features on EKO-Q, payment processing is handled by our third-party payment processor, Stripe. You will provide credit card or payment details directly to Stripe via the secure payment form. We do not store your full credit card information on our servers. We may retain non-sensitive payment details such as transaction ID, billing name, billing address, the last four digits of your card, or subscription status for record-keeping.
  • Sensor and Application Data: EKO-Q allows you to help you manage, store, and understand better your sensor data and allow you to get quality control protocol and insights from your measurements data. In doing so, the platform may collect data generated by those measurement devices (for example, measurement readings, device identifiers, timestamps, and related metadata). This measurement data is stored in your account so that you can view and analyze it. While those irradiance measurement data typically do not identify an individual, it is treated as part of your account data under this Policy.
  • Usage Logs and Technical Data: When you use EKO-Q, our systems automatically record certain information about your measurement data and your usage of the platform. This includes data such as your Internet Protocol (IP) address, browser type, device type, operating system, referring/exit pages, timestamps of access, and actions taken on the platform (e.g., pages or features used). These usage logs help us troubleshoot issues, secure the platform, and understand how users interact with EKO-Q. We may also collect general location information (e.g., city or country) inferred from your IP address to help us analyze usage by region.
  • Cookies and Session Data: We use cookies and similar technologies to keep you logged in and to remember your preferences (see Cookies and Analytics below for details). These may collect data like session tokens or other identifiers tied to your account.
  • Communications: If you contact EKO Instruments for support, feedback, or other inquiries regarding EKO-Q (for example, via email or through a support form), we will collect the information you choose to provide in that communication. This may include your contact details (like email or phone number) and the content of your message. We use this information to respond to you and resolve any issues.

We will make it clear when we request personal data from you, whether the provision of that data is mandatory or optional, and the consequences of not providing the data. We do not collect any special categories of personal data (such as sensitive personal information like health, genetic, or biometric data) through EKO-Q. Additionally, we do not intentionally collect any information from children (see Children’s Privacy below).

How We Use Your Data

We use the personal and technical information collected through EKO-Q for the following purposes:

  • To Provide and Operate the Service: We use your data to create and manage your account, authenticate you upon login, and deliver the functionality of the EKO-Q platform. For example, we use your measurements data to generate analyses and visualizations for you, and your account details to personalize your dashboard and settings.
  • To Communicate with You: We process your contact information to send important communications related to your use of EKO-Q. This includes sending transactional emails via our email service (Brevo) for actions like account activation, email verification, password resets, billing receipts, and notifications about significant changes or issues with the service. We may also respond to you directly via email or phone if you have reached out for support or have an open support ticket.
  • To Process Payments and Manage Subscriptions: If you make payments for EKO-Q, we use the data provided (through Stripe) to process your subscription or purchase, to prevent fraudulent transactions, and to keep records of your payment history. We might also use your contact and subscription data to notify you about renewal dates, failed payments, or invoice availability.
  • To Improve and Customize the Platform: We analyze usage data and feedback to understand how our users interact with EKO-Q. This analysis helps us troubleshoot technical issues, optimize user experience, and develop new features or enhancements. For instance, understanding which features are most used can guide our development priorities. We may also use aggregated measurements data (in anonymized form) to improve our analytics algorithms or product offerings.
  • To Ensure Security and Prevent Misuse: Your logs and other technical data are used to monitor for suspicious activities and to protect against unauthorized access, cyberattacks, fraud, or other misuse of our platform. We may use IP addresses and other identifiers to block malicious actors and to safeguard user accounts and data.
  • For Legal and Compliance Reasons: We may use your information to enforce our Terms of Service or other agreements, to comply with applicable laws and regulations, and to respond to lawful requests from authorities. For example, retaining certain data for auditing or compliance, or using your data to verify your identity if you exercise data rights requests.
  • Optional Marketing Communications: EKO-Q itself primarily sends service-related communications. We will not use your personal data for unsolicited marketing. However, if you are also an EKO Instruments newsletter subscriber or have explicitly opted in to receive marketing communications, we may send you updates about new products or services. You can opt out of marketing emails at any time, and opting out will not affect your access to EKO-Q. (Transactional emails and important service notices will still be sent as needed, as they are not promotional.)
  • Research and Development: In some cases, we may use anonymized or aggregated data (that cannot identify you) derived from your usage for internal research, analytics, and product development. For example, aggregated sensor performance metrics across all users might be studied to improve the accuracy of our instruments and services. Such aggregated data contains no personally identifiable information.

We do not sell your personal data to third parties. We only share your data with third parties as described in this Policy (for example, with service providers acting on our behalf, or when required by law). All the uses of data are aligned with the purposes for which the data was originally collected, and we will not use your information in a manner that is incompatible with those purposes without informing you and obtaining consent if required.

Cookies and Analytics

Like most web applications, EKO-Q uses cookies and similar tracking technologies to ensure the platform functions correctly and to enhance your user experience:

  • Functional Cookies: When you log into EKO-Q, our system uses an authentication cookie (or similar mechanism) to maintain your session. This cookie allows you to stay logged in as you navigate the platform and ensures that the correct account information is displayed to you. We may also use cookies to remember certain preferences (for example, your language or other settings) so that you don’t have to reconfigure them each time. These cookies are essential for providing the service and do not require consent under GDPR, as they are necessary for the operation of the site.
  • Analytics: To understand how users engage with EKO-Q and to improve our services, we use an analytics tool called Umami. Umami is a privacy-focused, self-hosted analytics platform. This means that any analytics data collected about the usage of EKO-Q is stored on our own servers (hosted on DigitalOcean) and is not shared with third-party analytics providers. Importantly, Umami does not use cookies and does not collect personally identifiable information. It tracks general usage metrics such as page views, buttons clicked, and geographic regions of users (using anonymized IP information). The analytics data helps us see overall trends (for example, how many users use a certain feature or which days the platform is most active) without profiling individual users. Because Umami does not store personal data or use tracking cookies, its use is designed to be GDPR-compliant and respectful of your privacy.
  • Other Tracking Technologies: Aside from cookies, we may use local storage or similar mechanisms for caching data on your browser to improve performance (for instance, storing a small bit of data so that a page loads faster on repeat visits). We do not use any third-party advertising networks or social media trackers on the EKO-Q platform.
  • Cookie Management: You have the ability to control and delete cookies if you wish. Most web browsers allow you to refuse new cookies, delete existing cookies, or notify you when new cookies are set. Please note, however, that if you disable or delete cookies related to EKO-Q, some core functionality (like staying logged in) may not work properly. Since our analytics do not rely on cookies, disabling cookies will not affect the data collected by Umami, but you are already protected as that data is anonymized. We do not display cookie consent banners within the EKO-Q application itself because we do not use non-essential or third-party cookies that require consent. If our practices change in the future, we will implement appropriate notice and consent mechanisms.

By using EKO-Q, you agree to our use of cookies and analytics as described above. For more information on our analytics configuration or any questions about cookies, feel free to contact us.

Third-Party Service Providers (Data Processors)

To operate the EKO-Q service efficiently, EKO Instruments relies on a few trusted third-party service providers. These third parties process data on our behalf and are contractually obligated to keep your information secure and use it only for the specific services they provide to us. Below are the key third-party processors we use, along with a description of what they do and what data may be shared with them:

  • DigitalOcean (Hosting & Storage): EKO-Q is hosted on DigitalOcean, a cloud infrastructure provider. Our servers are deployed in DigitalOcean’s USA data center. This means all data you provide to EKO-Q (your account information, sensor data, etc.) is stored on DigitalOcean’s infrastructure. DigitalOcean acts as a data processor by storing and handling data as we instruct. We have a Data Processing Agreement (DPA) with DigitalOcean, including Standard Contractual Clauses, to ensure your data is protected according to GDPR standards. DigitalOcean implements industry-standard security measures for physical and network security. (For more details on DigitalOcean’s privacy and security practices, you can refer to their privacy policy on their website.)
  • Stripe (Payment Processing): We use Stripe to handle all credit card and payment transactions for EKO-Q subscriptions or purchases. When you enter your payment information, it is transmitted directly to Stripe via a secure, encrypted connection and processed by Stripe. Stripe may collect or have access to personal data necessary for processing the payment and preventing fraud – this typically includes your name, email, billing address, and payment card details. Stripe is PCI-DSS compliant and is a certified GDPR-compliant processor. We have a DPA with Stripe to cover the protection of EU personal data. EKO Instruments does not receive or store your sensitive financial information (like full card numbers or CVC); we only receive transaction records and limited billing details from Stripe. Stripe may process your data in the United States or other jurisdictions. They too rely on mechanisms such as Standard Contractual Clauses for data transfers from the EU.
  • Brevo (Transactional Email Service): Brevo (formerly known as Sendinblue) is our email service provider for sending transactional and operational emails. We use Brevo to send emails such as account verification links, password reset emails, notifications about sensor reports, and other service-related communications. To do this, we provide Brevo with the necessary contact information (typically your name and email address, and the content of the email to send). Brevo is a company based in the EU (France) and stores data on secure servers. They act as a data processor for us, meaning they only use your data to send emails as instructed by EKO-Q. Brevo is GDPR-compliant and we have agreements in place to ensure the safety of your data. They do not use your email for their own purposes or marketing, and they do not have rights to share it.
  • Umami (Analytics Platform): As described in the Cookies and Analytics section, we use the open-source Umami software for analytics. Although Umami itself is a third-party tool, in our case it is self-hosted by EKO Instruments on our own infrastructure. This means that no external party is receiving the analytics data; it remains within our DigitalOcean servers and is processed under our control. Thus, Umami is not a separate data processor entity like the others listed here, but we mention it for transparency because it’s a third-party software. The data collected via Umami (e.g., page view counts, device types) is not personal data and is stored in our database. No user-identifiable information is sent to any external analytics provider.
  • Lucisun LuData (Satellite Irradiance and Meteo Reanalysis data provider): We rely on data from Lucisun LuData to supplement and cross-check the irradiance readings captured by your on-site pyranometers. Pyranometers serve as our core reference for local, ground-truth measurements. Lucisun LuData’s satellite-based irradiance and meteorological reanalysis data help provide an external baseline for scenarios in which local measurements may be affected by unique site conditions (e.g., shading, localized weather, and other sensor issues).
    • Data shared: To retrieve relevant irradiance and weather data, EKO-Q may send minimal location information (such as approximate GPS coordinates) to Lucisun LuData. No personal details are included beyond what is strictly necessary for matching and delivering the relevant satellite or meteorological data.
    • Data Processing & Protection: Lucisun LuData acts as a data processor bound by contract to use this data solely to fulfill our requested services. We have a Data Processing Agreement (DPA) in place, including Standard Contractual Clauses where necessary, to ensure adherence to GDPR and similar data protection standards.
    • International Data Transfers: Depending on their infrastructure, Lucisun LuData may process data in the EU or in other jurisdictions. When transfers occur outside the EU/EEA, recognized mechanisms (e.g., Standard Contractual Clauses) are used.
    • Security Measures: Lucisun LuData implements robust security measures to protect both data in transit and at rest. They do not store or use any shared data beyond providing the requested satellite and reanalysis details for EKO-Q. For further information on their data handling, please consult their publicly available privacy policy.
  • CAMS radiation service (Satellite Irradiance data provider): CAMS (Copernicus Atmosphere Monitoring Service) Radiation Service provides satellite-derived solar radiation data that we use alongside Lucisun to provide to our users more choice when doing their analysis.
    • Data Shared: To request location-specific irradiance data, EKO-Q sends latitude/longitude or similarly minimal location references to CAMS. We do not share personal identifiers; only the geographic information necessary to pull the corresponding radiation data.
    • Data Processing & Protection: As an EU-based service, CAMS operates under strict data protection regulations. It processes only the limited geographic data needed to provide irradiance outputs and does not collect additional personal information. Any agreements or legal mechanisms in place (e.g., Standard Contractual Clauses) ensure compliance with GDPR requirements for any data transfers outside the EU.
    • Security Measures: CAMS implements comprehensive technical and organizational safeguards to protect data integrity and confidentiality. They do not use or retain your location data for any purpose beyond fulfilling EKO-Q’s irradiance requests. You can find more details on their website regarding privacy and data handling.

We ensure that all third-party processors that handle EKO-Q user data are bound by strong privacy terms. They are not allowed to access or use your data for any purpose other than providing their service to us. We do not share your personal data with any third parties for their own marketing or purposes unrelated to EKO-Q. Aside from the providers above, the only other circumstances in which we might share data are: (a) if we are required to by law or government authority (such as in response to a court order or regulatory demand), or (b) if we need to disclose information to our professional advisors (e.g., lawyers, auditors) who are also bound to confidentiality, or (c) in the event of a business transfer (for instance, if EKO-Q or EKO Instruments undergoes a merger or acquisition, in which case the new owners would continue to honor the commitments in this Policy).

International Data Transfers

Because EKO Instruments operates globally, your data may be transferred to and stored in countries outside of your own. In particular, any personal data collected through EKO-Q will be transferred to the United States, because our application servers and databases are located in the USA region via DigitalOcean. This means that if you are located in the European Economic Area (EEA) or the United Kingdom, your personal information is transferred from the EEA/UK to the U.S. for processing.

  • Data Protection Safeguards: We understand that the U.S. is not currently deemed to have an “adequate” level of data protection by the European Commission. To ensure that your data remains protected to EU GDPR standards when it is transferred internationally, we have put in place appropriate safeguards, such as European Commission-approved Standard Contractual Clauses (SCCs) with our U.S.-based processors (e.g., DigitalOcean and Stripe). These contractual clauses obligate the recipients of the data to protect it according to the GDPR’s requirements. In addition, where possible, we implement additional technical measures like encryption both in transit and at rest, as well as policies to minimize who can access your data.
  • Access by EKO Global Offices: EKO Instruments Co., Ltd. is based in Japan, and we have subsidiaries and affiliates in other countries (including in the EU and the US). The data you provide may be accessed by authorized EKO personnel in these jurisdictions strictly on a need-to-know basis (for example, a support request you make might be handled by our EU office, or technical maintenance might be done by teams in Japan or elsewhere). All such internal transfers are covered by intra-group agreements that include data protection obligations.

By using the EKO-Q platform, you acknowledge that your personal data will be transferred to and processed in the United States and potentially other countries outside of your home country. We will, however, always protect your information as described in this Privacy Policy, regardless of where it is processed. If we need to transfer your data to any third party or country not covered by an adequacy decision, we will do so in accordance with GDPR Articles 44-49 (for instance, using SCCs, obtaining your consent where appropriate, or other valid transfer mechanisms). If you would like more information about our international data transfer practices or copies of the relevant safeguards in place, please contact us and we will be happy to provide further details.

Data Retention

We will retain your personal data only for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. The retention period can vary depending on the type of data and the purpose of processing. Here is a summary of our retention practices:

  • Account Data: We retain the personal information associated with your EKO-Q account (such as your profile info, sensor data, and usage logs) for as long as your account is active. If you choose to deactivate your account or request deletion, we will initiate the deletion of your personal data from our production systems. Inactive accounts may be retained for a reasonable period (for example, if your subscription lapses, we might keep your account data for a certain number of months in case you reactivate, but we will inform you of such policies in advance).
  • Sensor Data: Measurements data are collected and stored in EKO-Q and will be retained as long as you have an active account, so that you can access historical measurements. You have the ability to delete certain datasets or entries via the platform; deleting such data will remove it from active databases, though it may persist in backups for a limited time (see below).
  • Transaction and Billing Records: We keep records of transactions, invoices, and related billing information for at least the minimum duration required by tax and financial laws. For example, in many jurisdictions, we are legally required to keep invoice and payment records for a number of years (commonly 7 years) for auditing purposes. This means that if you made a purchase, some basic personal data tied to that purchase (like your name, company and billing details, payment amount, and date) may be retained even after your account is deleted, solely for legal compliance.
  • Support Communications: If you contacted us for support, we may retain those communications (including emails or ticket records) for a period of time after resolution. This helps us keep track of service history and improve our support processes. Typically, support records are retained for a few years, unless you request a deletion and we have no overriding reason to keep them.
  • Analytics Data: Analytics data collected via Umami is generally kept in aggregate form. Since this data does not identify users, we may keep aggregate usage statistics indefinitely to observe long-term trends. However, raw log data that could be tied to IP addresses is usually rotated or deleted within a short timeframe. For instance, server logs containing IP addresses are typically retained for security analysis for a few weeks to a few months, and then automatically purged or anonymized.
  • Backups: We perform regular backups of our database and systems to ensure we can recover from downtime or disasters. These backups are encrypted and stored securely. Backup files are retained for a limited retention cycle (e.g., backups might be kept for 30-60 days before being overwritten with newer backups). If you request deletion of your data, we will remove your data from our live systems and it will no longer be used, but it might remain in encrypted backups until those backups expire and are replaced. We treat data in backups as protected and will not restore or use deleted data unless absolutely necessary for security or legal reasons.

After the applicable retention period has elapsed, or upon your valid request for erasure, we will either securely delete or anonymize your personal data so that it can no longer be associated with you. If complete deletion (for example, from backups) is not immediately feasible, we will ensure the data is isolated and protected until deletion is possible.

Your Rights Under GDPR

If you are in the European Union, the United Kingdom, or other jurisdictions with similar data protection laws, you have certain rights regarding your personal data. EKO Instruments is committed to honoring these rights. Even if you are not in those regions, we extend many of these core rights to all our users as part of our commitment to privacy. Under GDPR (and equivalent laws), you have the following rights:

  • Right of Access: You have the right to request confirmation of whether we are processing your personal data, and if so, to request a copy of the personal data we hold about you. This allows you to know and verify the lawfulness of our processing.
  • Right to Rectification: If any of your personal information is inaccurate or incomplete, you have the right to ask us to correct or update it. We encourage you to keep your profile information up-to-date, and you may correct some of this directly in your account settings. For any details you cannot update yourself, you can request that we make the correction.
  • Right to Erasure: This is also known as the “right to be forgotten.” You may request that we delete your personal data when it is no longer necessary for us to retain it. You can delete your EKO-Q account via the platform interface or by contacting us. Upon such a request, we will erase your personal data, provided we do not have a valid legal reason to continue processing it (for example, we might need to keep certain transaction records as noted earlier). We will also inform any third-party processors to delete data they hold on our behalf, to the extent required by law.
  • Right to Restrict Processing: You have the right to ask us to limit the processing of your personal data in certain circumstances. For instance, if you contest the accuracy of your data, you can request we restrict processing while we verify the information. Or if you object to our processing based on legitimate interests, you can request restriction pending our assessment of whether our interests override yours. When processing is restricted, we can still store your data but will not use it further until the restriction is lifted.
  • Right to Object: You have the right to object to our processing of your personal data when that processing is based on legitimate interests or public interest. If you object, we will evaluate whether our legitimate grounds for processing outweigh your rights and freedoms. You also have an unconditional right to object to your data being used for direct marketing purposes. In practice, we do not use your EKO-Q data for unsolicited marketing without consent, but if you ever receive marketing communications from us, you can opt-out at any time.
  • Right to Data Portability: You have the right to receive your personal data that you have provided to us in a structured, commonly used, machine-readable format, and the right to have that data transmitted to another controller where technically feasible. In plain terms, this means you can ask for an export of your data (for example, your sensor datasets or account details) to take to another service. We will help by providing your data in a CSV or similar standard format. Note that this right applies to data processed by us by automated means, where the processing is based on your consent or on a contract.
  • Right to Withdraw Consent: If we rely on your consent for any part of processing, you have the right to withdraw that consent at any time. For example, if you consented to receive a newsletter, you can unsubscribe later. Withdrawing consent will not affect the lawfulness of any processing we carried out before your withdrawal.
  • Right to Lodge a Complaint: If you believe that we have infringed your data protection rights or processed your data unlawfully, you have the right to file a complaint with a supervisory authority. For EU users, this would typically be your country’s Data Protection Authority (DPA). For UK users, it’s the Information Commissioner’s Office (ICO). We kindly request that you attempt to resolve any concerns with us first, by contacting us, and we will do our best to address them.

To exercise any of your rights, please contact us using the information provided in the Contact section below. We may need to verify your identity before fulfilling certain requests (to ensure we don’t disclose data to an unauthorized person). We will respond to your request as soon as possible and in any event within one month, as required by GDPR. If for some reason we cannot fulfill your request (for example, if it adversely affects the rights of others or if we must retain data for legal reasons), we will explain the reasoning to you.

Please note that these rights are subject to some conditions and exceptions. For example, the right to erasure can’t be used to demand deletion of data that we are obligated to keep by law, and data portability applies only to information you have provided to us. However, we fully intend to honor your requests to the fullest extent possible.

Children’s Privacy

EKO-Q is a professional platform and is not intended for use by children. We do not knowingly allow anyone under the age of 16 to register an account or use the service. We do not intentionally collect personal information from children under 16 years of age. If you are under 16, please do not use this platform or submit any personal data to us. In the event that we learn we have collected personal data from a child under 16 (for instance, if a child fraudulently creates an account), we will take immediate steps to delete that information. For parents or guardians: if you discover that a minor under your care has provided personal data to EKO-Q without your consent, please contact us and we will remove the data and terminate the child’s account. (For residents in jurisdictions where the minimum age may be lower (e.g., 13 in some countries), we will respect those legal age limits accordingly.)

Contact Us

If you have any questions, concerns, or requests regarding this Privacy & Data Protection Policy or the handling of your personal data, please reach out to us. We are here to help and will respond promptly.

  • Data Controller: The data controller responsible for your information is EKO Instruments Co., Ltd., the owner of the EKO-Q platform. EKO Instruments has offices in the EU, US, and Japan.
  • Email: You may email our data protection team at eko-q@eko-instruments.com. Please include "EKO-Q Privacy Inquiry" in the subject line for quicker routing.
  • Online Contact Form: You can also send us a message through the contact form on our website (found on the EKO Instruments Contact Us page). Simply mention that your inquiry is about EKO-Q and privacy.
  • Postal Mail: If you prefer, you can write to us at our European office:
    EKO Instruments Europe B.V.
    Lulofsstraat 55, 2521 AL, The Hague, The Netherlands
    Please include attention to "Privacy Officer - EKO-Q".
    (You may also contact our headquarters in Japan at EKO Instruments Co., Ltd., but contacting the Europe office may lead to a faster response for GDPR-related queries.)

We will do our best to address any questions or issues you have about your personal data. If you contact us to exercise any of your data rights, please provide sufficient information for us to verify your identity and locate your data (for example, the email associated with your EKO-Q account and the specific request). For certain requests like data access or deletion, we may need to ask for additional verification or details for security reasons.

Thank you for reading our Privacy & Data Protection Policy. Your trust is important to us, and we are continuously working to maintain and improve the security and transparency of the EKO-Q platform. We encourage you to review this Policy periodically for any updates. By continuing to use EKO-Q, you acknowledge that you have read and understood this Policy. If you do not agree with any aspect of this Policy, please discontinue use of the platform and contact us to address your concerns.

Updated at: 17/04/2025