Global Commitment to Privacy
EKO Instruments is committed to protecting your personal data. We abide by all applicable laws and regulations, with a particular focus on the EU General Data Protection Regulation (GDPR) as our global standard for data privacy. We may update this Privacy & Data Protection Policy from time to time to reflect changes in our practices or legal requirements. Any changes will be posted on this page, and where appropriate, notified to you. This policy is effective from April 12, 2025.
Introduction
EKO-Q is a web-based software-as-a-service (SaaS) platform provided by EKO Instruments for both business (B2B) and individual (B2C) users. This Privacy Policy explains what types of information we collect through the EKO-Q application, how we use and protect that information, and the rights you have in relation to your personal data. It applies when you access EKO-Q , its Application Programming Interface(s) or any other interface related to it (related apps, marketing dashboard, analytical dashboards, etc.). Protecting your privacy and personal information is one of our top priorities. If you have any questions about this Policy or how EKO Instruments handles your data, please contact us using the details in the Contact section below.
Consent and Scope
By registering for or using the EKO-Q platform, you agree to this Privacy & Data Protection Policy and consent to the collection, use, and processing of your information as described herein. This Policy applies to all users of the EKO-Q web application and related services, whether you access the service as an individual consumer or on behalf of a company or other organization. It covers personal data collected through your use of EKO-Q. This Policy does not cover any offline data processing or interactions you may have with EKO Instruments outside of the EKO-Q platform (for example, through our corporate website or in person), which may be subject to separate privacy notices.
Types of Data We Collect
When you use EKO-Q, we collect several types of data to provide and improve our services. We only collect data that is necessary for the purposes described in this Policy. The types of data we collect include:
- Account Information: When you register an account, we collect personal identifiers such as your name and email address. If you register on behalf of a business, we may also collect your company name, company address, industry, and VAT ID (for billing and tax purposes). You will also create login credentials (such as a password) to secure your account.
- Contact and Profile Details: You may provide additional contact information like a phone number or job title, and other profile details at your discretion. These details help us communicate with you and personalize your experience.
- Payment Information: If you purchase a subscription or paid features on EKO-Q, payment processing is handled by our third-party payment processor, Stripe. You will provide credit card or payment details directly to Stripe via the secure payment form. We do not store your full credit card information on our servers. We may retain non-sensitive payment details such as transaction ID, billing name, billing address, the last four digits of your card, or subscription status for record-keeping.
- Sensor and Application Data: EKO-Q allows you to help you manage, store, and understand better your sensor data and allow you to get quality control protocol and insights from your measurements data. In doing so, the platform may collect data generated by those measurement devices (for example, measurement readings, device identifiers, timestamps, and related metadata). This measurement data is stored in your account so that you can view and analyze it. While those irradiance measurement data typically do not identify an individual, it is treated as part of your account data under this Policy.
- Usage Logs and Technical Data: When you use EKO-Q, our systems automatically record certain information about your measurement data and your usage of the platform. This includes data such as your Internet Protocol (IP) address, browser type, device type, operating system, referring/exit pages, timestamps of access, and actions taken on the platform (e.g., pages or features used). These usage logs help us troubleshoot issues, secure the platform, and understand how users interact with EKO-Q. We may also collect general location information (e.g., city or country) inferred from your IP address to help us analyze usage by region.
- Cookies and Session Data: We use cookies and similar technologies to keep you logged in and to remember your preferences (see Cookies and Analytics below for details). These may collect data like session tokens or other identifiers tied to your account.
- Communications: If you contact EKO Instruments for support, feedback, or other inquiries regarding EKO-Q (for example, via email or through a support form), we will collect the information you choose to provide in that communication. This may include your contact details (like email or phone number) and the content of your message. We use this information to respond to you and resolve any issues.
We will make it clear when we request personal data from you, whether the provision of that data is mandatory or optional, and the consequences of not providing the data. We do not collect any special categories of personal data (such as sensitive personal information like health, genetic, or biometric data) through EKO-Q. Additionally, we do not intentionally collect any information from children (see Children’s Privacy below).
Legal Basis for Processing
Under GDPR, EKO Instruments must have a valid legal basis to process your personal data. Depending on the context, one or more of the following legal bases may apply:
- Performance of a Contract: We process personal data to provide the EKO-Q services you have requested. For example, we require your name and email to create and administer your user account, and we use your data (like measurements inputs or usage actions) to deliver the platform’s functionality. Processing your data for billing and to provide customer support is also based on fulfilling our contractual obligations to you as a user.
- Legitimate Interests: We may process certain data as necessary for our legitimate business interests, provided those interests are not overridden by your data protection rights. For instance, it is in our legitimate interest to collect usage logs and analytics data to improve our platform’s performance and features, to ensure the security of our service (e.g., detecting fraud or misuse), and to communicate important service updates. When we rely on this basis, we consider and balance any potential impact on your rights.
- Consent: In some cases, we rely on your consent to process personal data. For example, if we ever want to use your personal data for a purpose that requires consent (such as using your email to send promotional marketing not related to the core service), we will ask for your explicit consent. You have the right to withdraw your consent at any time. (Note: Using EKO-Q itself and the data processing involved in providing the service is generally not based on consent but on the other bases listed here, since the processing is necessary for the service.)
- Legal Obligation: We also process personal data when required to comply with our legal obligations. For example, for financial and tax regulations we may need to retain invoice information including your name, company details, VAT ID, and transaction history. If authorities lawfully require us to provide personal data (such as for law enforcement or regulatory purposes), we will do so under the legal obligation basis.
- Vital Interests or Public Interest: In very unlikely scenarios, we might process data to protect someone’s vital interests (life or safety) or for a task in the public interest, but these bases are generally not applicable to the EKO-Q service’s typical operations.
We will always ensure that we have a valid legal ground to collect and use your data, and we will document our decision-making for these bases as required by GDPR.
How We Use Your Data
We use the personal and technical information collected through EKO-Q for the following purposes:
- To Provide and Operate the Service: We use your data to create and manage your account, authenticate you upon login, and deliver the functionality of the EKO-Q platform. For example, we use your measurements data to generate analyses and visualizations for you, and your account details to personalize your dashboard and settings.
- To Communicate with You: We process your contact information to send important communications related to your use of EKO-Q. This includes sending transactional emails via our email service (Brevo) for actions like account activation, email verification, password resets, billing receipts, and notifications about significant changes or issues with the service. We may also respond to you directly via email or phone if you have reached out for support or have an open support ticket.
- To Process Payments and Manage Subscriptions: If you make payments for EKO-Q, we use the data provided (through Stripe) to process your subscription or purchase, to prevent fraudulent transactions, and to keep records of your payment history. We might also use your contact and subscription data to notify you about renewal dates, failed payments, or invoice availability.
- To Improve and Customize the Platform: We analyze usage data and feedback to understand how our users interact with EKO-Q. This analysis helps us troubleshoot technical issues, optimize user experience, and develop new features or enhancements. For instance, understanding which features are most used can guide our development priorities. We may also use aggregated measurements data (in anonymized form) to improve our analytics algorithms or product offerings.
- To Ensure Security and Prevent Misuse: Your logs and other technical data are used to monitor for suspicious activities and to protect against unauthorized access, cyberattacks, fraud, or other misuse of our platform. We may use IP addresses and other identifiers to block malicious actors and to safeguard user accounts and data.
- For Legal and Compliance Reasons: We may use your information to enforce our Terms of Service or other agreements, to comply with applicable laws and regulations, and to respond to lawful requests from authorities. For example, retaining certain data for auditing or compliance, or using your data to verify your identity if you exercise data rights requests.
- Optional Marketing Communications: EKO-Q itself primarily sends service-related communications. We will not use your personal data for unsolicited marketing. However, if you are also an EKO Instruments newsletter subscriber or have explicitly opted in to receive marketing communications, we may send you updates about new products or services. You can opt out of marketing emails at any time, and opting out will not affect your access to EKO-Q. (Transactional emails and important service notices will still be sent as needed, as they are not promotional.)
- Research and Development: In some cases, we may use anonymized or aggregated data (that cannot identify you) derived from your usage for internal research, analytics, and product development. For example, aggregated sensor performance metrics across all users might be studied to improve the accuracy of our instruments and services. Such aggregated data contains no personally identifiable information.
We do not sell your personal data to third parties. We only share your data with third parties as described in this Policy (for example, with service providers acting on our behalf, or when required by law). All the uses of data are aligned with the purposes for which the data was originally collected, and we will not use your information in a manner that is incompatible with those purposes without informing you and obtaining consent if required.
Third-Party Service Providers (Data Processors)
To operate the EKO-Q service efficiently, EKO Instruments relies on a few trusted third-party service providers. These third parties process data on our behalf and are contractually obligated to keep your information secure and use it only for the specific services they provide to us. Below are the key third-party processors we use, along with a description of what they do and what data may be shared with them:
- DigitalOcean (Hosting & Storage): EKO-Q is hosted on DigitalOcean, a cloud infrastructure provider. Our servers are deployed in DigitalOcean’s USA data center. This means all data you provide to EKO-Q (your account information, sensor data, etc.) is stored on DigitalOcean’s infrastructure. DigitalOcean acts as a data processor by storing and handling data as we instruct. We have a Data Processing Agreement (DPA) with DigitalOcean, including Standard Contractual Clauses, to ensure your data is protected according to GDPR standards. DigitalOcean implements industry-standard security measures for physical and network security. (For more details on DigitalOcean’s privacy and security practices, you can refer to their privacy policy on their website.)
- Stripe (Payment Processing): We use Stripe to handle all credit card and payment transactions for EKO-Q subscriptions or purchases. When you enter your payment information, it is transmitted directly to Stripe via a secure, encrypted connection and processed by Stripe. Stripe may collect or have access to personal data necessary for processing the payment and preventing fraud – this typically includes your name, email, billing address, and payment card details. Stripe is PCI-DSS compliant and is a certified GDPR-compliant processor. We have a DPA with Stripe to cover the protection of EU personal data. EKO Instruments does not receive or store your sensitive financial information (like full card numbers or CVC); we only receive transaction records and limited billing details from Stripe. Stripe may process your data in the United States or other jurisdictions. They too rely on mechanisms such as Standard Contractual Clauses for data transfers from the EU.
- Brevo (Transactional Email Service): Brevo (formerly known as Sendinblue) is our email service provider for sending transactional and operational emails. We use Brevo to send emails such as account verification links, password reset emails, notifications about sensor reports, and other service-related communications. To do this, we provide Brevo with the necessary contact information (typically your name and email address, and the content of the email to send). Brevo is a company based in the EU (France) and stores data on secure servers. They act as a data processor for us, meaning they only use your data to send emails as instructed by EKO-Q. Brevo is GDPR-compliant and we have agreements in place to ensure the safety of your data. They do not use your email for their own purposes or marketing, and they do not have rights to share it.
- Umami (Analytics Platform): As described in the Cookies and Analytics section, we use the open-source Umami software for analytics. Although Umami itself is a third-party tool, in our case it is self-hosted by EKO Instruments on our own infrastructure. This means that no external party is receiving the analytics data; it remains within our DigitalOcean servers and is processed under our control. Thus, Umami is not a separate data processor entity like the others listed here, but we mention it for transparency because it’s a third-party software. The data collected via Umami (e.g., page view counts, device types) is not personal data and is stored in our database. No user-identifiable information is sent to any external analytics provider.
- Lucisun LuData (Satellite Irradiance and Meteo Reanalysis data provider): We rely on data from Lucisun LuData to supplement and cross-check the irradiance readings captured by your on-site pyranometers. Pyranometers serve as our core reference for local, ground-truth measurements. Lucisun LuData’s satellite-based irradiance and meteorological reanalysis data help provide an external baseline for scenarios in which local measurements may be affected by unique site conditions (e.g., shading, localized weather, and other sensor issues).
- Data shared: To retrieve relevant irradiance and weather data, EKO-Q may send minimal location information (such as approximate GPS coordinates) to Lucisun LuData. No personal details are included beyond what is strictly necessary for matching and delivering the relevant satellite or meteorological data.
- Data Processing & Protection: Lucisun LuData acts as a data processor bound by contract to use this data solely to fulfill our requested services. We have a Data Processing Agreement (DPA) in place, including Standard Contractual Clauses where necessary, to ensure adherence to GDPR and similar data protection standards.
- International Data Transfers: Depending on their infrastructure, Lucisun LuData may process data in the EU or in other jurisdictions. When transfers occur outside the EU/EEA, recognized mechanisms (e.g., Standard Contractual Clauses) are used.
- Security Measures: Lucisun LuData implements robust security measures to protect both data in transit and at rest. They do not store or use any shared data beyond providing the requested satellite and reanalysis details for EKO-Q. For further information on their data handling, please consult their publicly available privacy policy.
- CAMS radiation service (Satellite Irradiance data provider): CAMS (Copernicus Atmosphere Monitoring Service) Radiation Service provides satellite-derived solar radiation data that we use alongside Lucisun to provide to our users more choice when doing their analysis.
- Data Shared: To request location-specific irradiance data, EKO-Q sends latitude/longitude or similarly minimal location references to CAMS. We do not share personal identifiers; only the geographic information necessary to pull the corresponding radiation data.
- Data Processing & Protection: As an EU-based service, CAMS operates under strict data protection regulations. It processes only the limited geographic data needed to provide irradiance outputs and does not collect additional personal information. Any agreements or legal mechanisms in place (e.g., Standard Contractual Clauses) ensure compliance with GDPR requirements for any data transfers outside the EU.
- Security Measures: CAMS implements comprehensive technical and organizational safeguards to protect data integrity and confidentiality. They do not use or retain your location data for any purpose beyond fulfilling EKO-Q’s irradiance requests. You can find more details on their website regarding privacy and data handling.
We ensure that all third-party processors that handle EKO-Q user data are bound by strong privacy terms. They are not allowed to access or use your data for any purpose other than providing their service to us. We do not share your personal data with any third parties for their own marketing or purposes unrelated to EKO-Q. Aside from the providers above, the only other circumstances in which we might share data are: (a) if we are required to by law or government authority (such as in response to a court order or regulatory demand), or (b) if we need to disclose information to our professional advisors (e.g., lawyers, auditors) who are also bound to confidentiality, or (c) in the event of a business transfer (for instance, if EKO-Q or EKO Instruments undergoes a merger or acquisition, in which case the new owners would continue to honor the commitments in this Policy).
International Data Transfers
Because EKO Instruments operates globally, your data may be transferred to and stored in countries outside of your own. In particular, any personal data collected through EKO-Q will be transferred to the United States, because our application servers and databases are located in the USA region via DigitalOcean. This means that if you are located in the European Economic Area (EEA) or the United Kingdom, your personal information is transferred from the EEA/UK to the U.S. for processing.
- Data Protection Safeguards: We understand that the U.S. is not currently deemed to have an “adequate” level of data protection by the European Commission. To ensure that your data remains protected to EU GDPR standards when it is transferred internationally, we have put in place appropriate safeguards, such as European Commission-approved Standard Contractual Clauses (SCCs) with our U.S.-based processors (e.g., DigitalOcean and Stripe). These contractual clauses obligate the recipients of the data to protect it according to the GDPR’s requirements. In addition, where possible, we implement additional technical measures like encryption both in transit and at rest, as well as policies to minimize who can access your data.
- Access by EKO Global Offices: EKO Instruments Co., Ltd. is based in Japan, and we have subsidiaries and affiliates in other countries (including in the EU and the US). The data you provide may be accessed by authorized EKO personnel in these jurisdictions strictly on a need-to-know basis (for example, a support request you make might be handled by our EU office, or technical maintenance might be done by teams in Japan or elsewhere). All such internal transfers are covered by intra-group agreements that include data protection obligations.
By using the EKO-Q platform, you acknowledge that your personal data will be transferred to and processed in the United States and potentially other countries outside of your home country. We will, however, always protect your information as described in this Privacy Policy, regardless of where it is processed. If we need to transfer your data to any third party or country not covered by an adequacy decision, we will do so in accordance with GDPR Articles 44-49 (for instance, using SCCs, obtaining your consent where appropriate, or other valid transfer mechanisms). If you would like more information about our international data transfer practices or copies of the relevant safeguards in place, please contact us and we will be happy to provide further details.
Data Retention
We will retain your personal data only for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. The retention period can vary depending on the type of data and the purpose of processing. Here is a summary of our retention practices:
- Account Data: We retain the personal information associated with your EKO-Q account (such as your profile info, sensor data, and usage logs) for as long as your account is active. If you choose to deactivate your account or request deletion, we will initiate the deletion of your personal data from our production systems. Inactive accounts may be retained for a reasonable period (for example, if your subscription lapses, we might keep your account data for a certain number of months in case you reactivate, but we will inform you of such policies in advance).
- Sensor Data: Measurements data are collected and stored in EKO-Q and will be retained as long as you have an active account, so that you can access historical measurements. You have the ability to delete certain datasets or entries via the platform; deleting such data will remove it from active databases, though it may persist in backups for a limited time (see below).
- Transaction and Billing Records: We keep records of transactions, invoices, and related billing information for at least the minimum duration required by tax and financial laws. For example, in many jurisdictions, we are legally required to keep invoice and payment records for a number of years (commonly 7 years) for auditing purposes. This means that if you made a purchase, some basic personal data tied to that purchase (like your name, company and billing details, payment amount, and date) may be retained even after your account is deleted, solely for legal compliance.
- Support Communications: If you contacted us for support, we may retain those communications (including emails or ticket records) for a period of time after resolution. This helps us keep track of service history and improve our support processes. Typically, support records are retained for a few years, unless you request a deletion and we have no overriding reason to keep them.
- Analytics Data: Analytics data collected via Umami is generally kept in aggregate form. Since this data does not identify users, we may keep aggregate usage statistics indefinitely to observe long-term trends. However, raw log data that could be tied to IP addresses is usually rotated or deleted within a short timeframe. For instance, server logs containing IP addresses are typically retained for security analysis for a few weeks to a few months, and then automatically purged or anonymized.
- Backups: We perform regular backups of our database and systems to ensure we can recover from downtime or disasters. These backups are encrypted and stored securely. Backup files are retained for a limited retention cycle (e.g., backups might be kept for 30-60 days before being overwritten with newer backups). If you request deletion of your data, we will remove your data from our live systems and it will no longer be used, but it might remain in encrypted backups until those backups expire and are replaced. We treat data in backups as protected and will not restore or use deleted data unless absolutely necessary for security or legal reasons.
After the applicable retention period has elapsed, or upon your valid request for erasure, we will either securely delete or anonymize your personal data so that it can no longer be associated with you. If complete deletion (for example, from backups) is not immediately feasible, we will ensure the data is isolated and protected until deletion is possible.
Your Rights Under GDPR
If you are in the European Union, the United Kingdom, or other jurisdictions with similar data protection laws, you have certain rights regarding your personal data. EKO Instruments is committed to honoring these rights. Even if you are not in those regions, we extend many of these core rights to all our users as part of our commitment to privacy. Under GDPR (and equivalent laws), you have the following rights:
- Right of Access: You have the right to request confirmation of whether we are processing your personal data, and if so, to request a copy of the personal data we hold about you. This allows you to know and verify the lawfulness of our processing.
- Right to Rectification: If any of your personal information is inaccurate or incomplete, you have the right to ask us to correct or update it. We encourage you to keep your profile information up-to-date, and you may correct some of this directly in your account settings. For any details you cannot update yourself, you can request that we make the correction.
- Right to Erasure: This is also known as the “right to be forgotten.” You may request that we delete your personal data when it is no longer necessary for us to retain it. You can delete your EKO-Q account via the platform interface or by contacting us. Upon such a request, we will erase your personal data, provided we do not have a valid legal reason to continue processing it (for example, we might need to keep certain transaction records as noted earlier). We will also inform any third-party processors to delete data they hold on our behalf, to the extent required by law.
- Right to Restrict Processing: You have the right to ask us to limit the processing of your personal data in certain circumstances. For instance, if you contest the accuracy of your data, you can request we restrict processing while we verify the information. Or if you object to our processing based on legitimate interests, you can request restriction pending our assessment of whether our interests override yours. When processing is restricted, we can still store your data but will not use it further until the restriction is lifted.
- Right to Object: You have the right to object to our processing of your personal data when that processing is based on legitimate interests or public interest. If you object, we will evaluate whether our legitimate grounds for processing outweigh your rights and freedoms. You also have an unconditional right to object to your data being used for direct marketing purposes. In practice, we do not use your EKO-Q data for unsolicited marketing without consent, but if you ever receive marketing communications from us, you can opt-out at any time.
- Right to Data Portability: You have the right to receive your personal data that you have provided to us in a structured, commonly used, machine-readable format, and the right to have that data transmitted to another controller where technically feasible. In plain terms, this means you can ask for an export of your data (for example, your sensor datasets or account details) to take to another service. We will help by providing your data in a CSV or similar standard format. Note that this right applies to data processed by us by automated means, where the processing is based on your consent or on a contract.
- Right to Withdraw Consent: If we rely on your consent for any part of processing, you have the right to withdraw that consent at any time. For example, if you consented to receive a newsletter, you can unsubscribe later. Withdrawing consent will not affect the lawfulness of any processing we carried out before your withdrawal.
- Right to Lodge a Complaint: If you believe that we have infringed your data protection rights or processed your data unlawfully, you have the right to file a complaint with a supervisory authority. For EU users, this would typically be your country’s Data Protection Authority (DPA). For UK users, it’s the Information Commissioner’s Office (ICO). We kindly request that you attempt to resolve any concerns with us first, by contacting us, and we will do our best to address them.
To exercise any of your rights, please contact us using the information provided in the Contact section below. We may need to verify your identity before fulfilling certain requests (to ensure we don’t disclose data to an unauthorized person). We will respond to your request as soon as possible and in any event within one month, as required by GDPR. If for some reason we cannot fulfill your request (for example, if it adversely affects the rights of others or if we must retain data for legal reasons), we will explain the reasoning to you.
Please note that these rights are subject to some conditions and exceptions. For example, the right to erasure can’t be used to demand deletion of data that we are obligated to keep by law, and data portability applies only to information you have provided to us. However, we fully intend to honor your requests to the fullest extent possible.
Children’s Privacy
EKO-Q is a professional platform and is not intended for use by children. We do not knowingly allow anyone under the age of 16 to register an account or use the service. We do not intentionally collect personal information from children under 16 years of age. If you are under 16, please do not use this platform or submit any personal data to us. In the event that we learn we have collected personal data from a child under 16 (for instance, if a child fraudulently creates an account), we will take immediate steps to delete that information. For parents or guardians: if you discover that a minor under your care has provided personal data to EKO-Q without your consent, please contact us and we will remove the data and terminate the child’s account. (For residents in jurisdictions where the minimum age may be lower (e.g., 13 in some countries), we will respect those legal age limits accordingly.)
Contact Us
If you have any questions, concerns, or requests regarding this Privacy & Data Protection Policy or the handling of your personal data, please reach out to us. We are here to help and will respond promptly.
- Data Controller: The data controller responsible for your information is EKO Instruments Co., Ltd., the owner of the EKO-Q platform. EKO Instruments has offices in the EU, US, and Japan.
- Email: You may email our data protection team at eko-q@eko-instruments.com. Please include "EKO-Q Privacy Inquiry" in the subject line for quicker routing.
- Online Contact Form: You can also send us a message through the contact form on our website (found on the EKO Instruments Contact Us page). Simply mention that your inquiry is about EKO-Q and privacy.
- Postal Mail: If you prefer, you can write to us at our European office:EKO Instruments Europe B.V.
Lulofsstraat 55, 2521 AL, The Hague, The Netherlands
Please include attention to "Privacy Officer - EKO-Q".(You may also contact our headquarters in Japan at EKO Instruments Co., Ltd., but contacting the Europe office may lead to a faster response for GDPR-related queries.)
We will do our best to address any questions or issues you have about your personal data. If you contact us to exercise any of your data rights, please provide sufficient information for us to verify your identity and locate your data (for example, the email associated with your EKO-Q account and the specific request). For certain requests like data access or deletion, we may need to ask for additional verification or details for security reasons.
Thank you for reading our Privacy & Data Protection Policy. Your trust is important to us, and we are continuously working to maintain and improve the security and transparency of the EKO-Q platform. We encourage you to review this Policy periodically for any updates. By continuing to use EKO-Q, you acknowledge that you have read and understood this Policy. If you do not agree with any aspect of this Policy, please discontinue use of the platform and contact us to address your concerns.
Updated at: 17/04/2025