CONFIDENTIALITY POLICY

(In force as of  25.05.2018)

Shelly Cloud (the Service) allows you to access and control a device form the Shelly home automation series (excluding the device Shelly Eye) and the data associated with them.

Controller of the personal data processed for the purposes related to the Shelly Cloud mobile application is ALLTERCO ROBOTICS EOOD, UIC: 202320104, having its seat and registered address in Sofia, No 103 Cherni Vruh Blvd.

The Data protection officer of ALTERCO ROBOTICS EOOD shall reply to all your queries concerning the processing and protection of personal data and shall make the process of exercising your data subject rights easier and more comprehensible. Establishing direct contact with him/her for your convenience and ease is being facilitated via email: dpo@allterco.com

ALLTERCO ROBOTICS EOOD strives to expand and diversify its portfolio of goods and services by collaborating and going into partnerships with mobile carriers in different countries. We wish to inform you about our new products, services, and promotions for which we need your consent: 

I consent to receive messages for new products, services, and promotions of ALLTERCO ROBOTICS EOOD:

              via an email from my profile

You may withdraw the consent provided above through the settings of the application Shelly Cloud. Upon withdrawal of the consent, processing of the respective type of personal data shall be terminated for the stated purposes. Withdrawal of consent shall not prejudice the legality of the processing based on consent given prior to its withdrawal.

 

  1.   The types of personal data we process:

 

on a contractual basis for the provision of the Service:

 

1.1. Profile data

-         E-mail address;

-         The serial number of a device from Shelly series;

-         Password;

1.2. Data concerning the Shelly device and the paired (connected) mobile devices

-         Model and device number of the Shelly device and paired mobile devices;

-         a version of the installed Shelly Cloud application, chosen language and time zone;

-         The IP address of the paired mobile device and the Shelly device;

 

On the basis of your explicit consent, expressed via the device settings or by a deliberate action by populating certain fields on the application:

 

1.3. Data derived from the settings of the Shelly Cloud application

-           Operations mode

-           Choosing periods of work and rest/sleep

-           Other input by you into the Shelly Cloud application in the application's and Shelly device’s functional parameters;

 

You may withdraw each and every consent provided above through the settings of the application and your mobile device. Upon withdrawal of the consent, processing of the respective type of personal data shall be terminated for the stated purposes. Withdrawal of consent shall not prejudice the legality of the processing based on consent given prior to its withdrawal.

 

ALTERCO ROBOTICS EOOD processes data for business analysis of the sales extrapolated from de-personified anonymous data (legitimate ground):

1.4. Anonymized data

-         Statistical information concerning the total number of active devices and their geographical allocation (general dispersal).

 

2.  Purposes of personal data processing;

2.1. Data concerning the profile for the purposes of:

-        Remote control of a Shelly device;

-        Provision of servicing and maintenance for removal of technical defects, limiting the access to the Service, etc.;

-        Email verification to ensure the security of data access for your profile and the Shelly device;

-         Sending messages for the purposes of direct marketing and advertisement upon explicit consent on your part;

-         Authentication when signing in to the application;

-          Password change;

2.2. Data concerning the Shelly device and the paired mobile devices for the purposes of:

-         Providing a connection between the Shelly device and the mobile device on which the application is installed;

-         Device Shelly Product Sheet Access Control;

-         Provision of services concerning servicing and maintenance for the correct functioning of the Shelly device;

-         Improving the Shelly Cloud Service;

-         Providing information on new services and products.

2.3. Anonymized data for the purposes of:

-         Statistical analysis of consumption and consumer demand in various regions. The identification of a concrete person from this information is impossible.

 

  1.   Third parties to whom we provide your personal information:

3.1. call centers that help us assist you in case of issues with the handling, configuration, and operation of the Shelly Cloud mobile application and the Shelly devices;

3.2. consultants in various fields in view of protection of our legitimate interests in the maintenance and improving the quality of the service, compliance with regulatory requirements, protection of legitimate rights and interests in court and administrative proceedings;

3.3. state bodies and institutions in connection to checks and probes performed by them in compliance with the legal requirements and restrictions;

3.4. Affiliated parties of ALLTERCO ROBOTICS EOOD in a connection with usage of shared technical and human resources, transformations, and others.

In regards to private individuals, we require and pay attention that the above stated third parties apply all required technical and organizational measures for the protection of such data.

 

  1.   The Data is processed in regards to the following time limits:

4.1. Profile data - until the account is deleted or up to 3 years following the last log-in into the application. The time limit is determined in view of the need to allow the Shelly device to be used in the event of its loss or theft and the subsequent rediscovery of the said item form its legal owner;

4.2. Device data for the Shelly device and the paired mobile devices - until termination of the Service;

4.3. Data provided on the basis of consent - until it is withdrawn, as provided, including through the settings of the application or the mobile device to which it is installed or deleted, if applicable, to the extent that the data is required for the use of certain functionality of the mobile application;

 

Following the expiration of the above stated time limit, the data is deleted and may not be retrieved and used any longer. The data shall not be deleted but shall continue to be processed only for the purposes of protection of our legitimate rights and interests or in compliance with our legitimate obligations, in the event that as of the date of expiration of the above stated time limit there is a pending court, administrative and pre-court proceedings – until its termination.

  1. Your rights as a data subject:

5.1. Right to access, including right to copy data undergoing processing:

 

5.2. Right to correct inaccurate personal data:

5.3. Right to delete („The right to be forgotten“) in the following cases:

The right to be forgotten is not an absolute right and might not be respected in cases provided for by law and because of a lack of reliable verification of your identity.

5.4. Right of limiting processing when:

In case of correction, deletion, or restriction of processing, we will notify every recipient whose personal data has been disclosed unless this is impossible or requires disproportionately huge efforts.

5.5. Right of portability of the data;

5.6. Right to object to the processing based on legitimate interest:

5.7. Right to object to the processing for the purposes of direct marketing:

5.8. Right to lodge a complaint with a supervisory in the Member State of your habitual residence, place of work, or place of the alleged infringement if you consider that the processing of personal data relating to you infringes GDPR.

 

You may exercise the aforementioned data subject rights after filling out a written predefined request form which you may receive from the business address of the Controller or via electronic means after contacting the Data Protection Officer and filling out the electronic form which you will receive in response.

            The response of our request will be delivered in within one month of receiving your written request form.

 

6. Used automated individual decision-making, including profiling (automated algorithms)

We do not use any automated algorithms and/or profiling.