Legal · Privacy
Privacy policy
Effective and last updated:
Solarverse is a solar operations platform operated by Cotidie Group, Serbia. This policy explains how we process personal data when you use Solarverse websites, mobile applications, connected services, support, and early-access forms.
1. Who is responsible for your data
Cotidie Group is the controller for Solarverse account, service, security, support, and early-access data. A customer organization may separately control personal data it places in Solarverse, including member access and plant information. In that context, we process the data to provide the service under the customer agreement.
Privacy questions and rights requests can be sent to hello@solarverse.app.
2. Data we process
- Account and access data: name, business email, password hash, email-verification state, organization memberships, roles, plant grants, invitations, sessions, device/browser information, IP address, and authentication security events.
- Organization and plant data: company identity, branding, plant names, addresses or coordinates, timezone, capacity, commissioning details, device inventory, and configuration entered by authorized operators.
- Operational data: inverter telemetry, production and energy readings, status, diagnostics, alerts, weather observations and forecasts, user acknowledgements, audit history, and service logs.
- Mobile and notification data: app environment, platform, push-subscription identifier, notification preferences, delivery status, and the limited workspace/site snapshot saved for home-screen widgets. Authentication tokens remain in the operating system's secure storage.
- Communications: early-access form details, including name, email, company, fleet information and message, plus support requests and our responses.
- Optional feature data: electricity bills and reviewed calculation inputs when you use Savings; bounded alert, diagnostic, aggregate telemetry, weather, performance, and equipment evidence when an authorized operator requests an AI Investigation; and authorization/consent records when you connect ChatGPT.
3. How we obtain data
We receive data from you, your employer or customer organization, an authorized installer, the site collector or edge device, and the web or mobile client. We also receive limited delivery, mapping, weather, email, and connected-service responses from our service providers.
4. Why we use data and our legal bases
- To provide, secure, support and administer Solarverse, fulfil customer agreements, authenticate users, display authorized plant data, and deliver requested notifications.
- To take steps requested before a contract, including responding to an early-access or product enquiry.
- For legitimate interests in service reliability, fraud and abuse prevention, troubleshooting, auditability, product safety, and understanding whether the service works as intended, balanced against affected users' rights.
- To meet legal, accounting, security, and regulatory obligations or to establish, exercise, or defend legal claims.
- With consent where consent is required, such as operating-system push permission or optional marketing communication. Consent can be withdrawn without affecting earlier lawful processing.
Solarverse may calculate alerts, health states and performance indicators, but does not make solely automated decisions that produce legal or similarly significant effects about an individual.
5. Cookies, SDKs and similar technology
The web application uses essential authentication and security cookies. The mobile application stores its session in platform secure storage. The web and mobile applications use OneSignal only when push is configured and the user enables notifications. We do not currently use third-party advertising cookies, sell personal data, or use personal data for cross-context behavioural advertising.
6. Service providers and disclosures
We disclose only the data needed for providers to perform services for us. Current provider categories include:
- EU application, database, network, object-storage, backup, and deployment infrastructure providers, including infrastructure used during a controlled migration or recovery operation.
- Resend for transactional and operational email.
- OneSignal and the relevant Apple or Google platform service for mobile and browser push delivery.
- Google Maps for maps and directions, and Open-Meteo for weather data. A plant's coordinates are sent only when needed for the requested feature.
- OpenAI when a user deliberately connects the read-only ChatGPT integration. Solarverse does not store ChatGPT prompts or conversations; OpenAI's handling is governed by the user's OpenAI product and workspace settings. See the connector privacy notice.
- Google's paid Gemini Developer API when an authorized owner, administrator, or technician deliberately requests an AI Investigation. Solarverse sends one bounded, non-identifying evidence package for that Alert. It excludes names, emails, workspace and plant names or identifiers, exact coordinates, device serials and connection details, credentials, raw telemetry, logs, and technician notes.
- Professional advisers, regulators, courts, or authorities when disclosure is legally required or necessary to protect rights and service security.
Source bills are not sent to an AI extraction provider in production unless that feature and provider have been separately approved, configured, and disclosed. Manual Savings entry does not require AI processing.
7. International transfers
Solarverse's core application, databases, backups, and service logs remain in approved European regions. Some communications, mapping, push, AI, or user-selected connected services may process limited data outside Serbia or the EEA. AI Investigations use Google's globally routed Gemini Developer API, so Solarverse cannot guarantee EU-only processing for the bounded evidence package. Where data-protection law requires it, we use an applicable adequacy decision, contractual safeguards, or another lawful transfer mechanism. You may contact us for information about safeguards relevant to your data.
8. Retention
We retain data only for as long as needed for the purposes above. The period depends on the type of data and customer relationship:
- Account, organization, plant and telemetry data are kept while the service or customer agreement is active and then for a limited period needed for export, recovery, legal obligations, disputes, and security.
- Ordinary sign-in sessions expire after seven days unless refreshed or revoked sooner. Verification links expire after one hour.
- Push identifiers remain until the device is disconnected, the preference is disabled, or the related account data is deleted.
- Early-access and support records remain while we evaluate or respond to the request and are periodically reviewed or deleted when no longer needed.
- Privacy and deletion request records are kept only as long as needed to verify, complete, and document the response, including any legal compliance that must be demonstrated.
- A Savings source bill can be deleted independently. Finalized calculation and audit records may be retained where needed to preserve requested business records and explain the calculation.
- Investigation inputs and validated results remain in Solarverse according to the related Alert and customer record. Google states that paid Gemini API inputs and outputs are not used to improve its products. Google may retain prompts, contextual information, and outputs for up to 55 days for abuse monitoring. Solarverse does not enable provider tools, file storage, or provider-side retrieval for this feature.
- Deleted production data may remain temporarily in encrypted backups until the applicable backup rotation expires. The current pilot rotation keeps hourly, daily, weekly and monthly recovery points, with the oldest routine monthly snapshot retained for up to 12 months. Backup data is not restored except for disaster recovery.
9. Security
We use measures intended to protect data against unauthorized access, alteration, loss and disclosure, including HTTPS, restricted administrative access, secure session storage, least-privilege service and database roles, tenant isolation, encrypted off-site backups, monitoring, and audit records. No service can promise absolute security; please report suspected misuse promptly.
10. Your rights and account deletion
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or a copy of your personal data, and may object to certain processing or withdraw consent. You may also complain to the competent data-protection authority, including the Serbian Commissioner for Information of Public Importance and Personal Data Protection where applicable.
An organization administrator may need to preserve or transfer operational records owned by the customer before an individual account is deleted.
Request account and personal-data deletion
Submit the email associated with your account. We'll verify the request before deleting or de-identifying eligible personal data. Do not include a password, token, or other secret.
11. Children
Solarverse is a business service for solar operators and is not directed to children. We do not knowingly create accounts for anyone under 18. Contact us if you believe a child has provided personal data.
12. Changes to this policy
We may update this policy when the product, providers, or legal requirements change. We will publish the revised date here and provide additional notice where a change materially affects users or requires consent.
13. Contact
Cotidie Group · Serbia
Solarverse privacy contact: hello@solarverse.app
