Privacy Policy

Effective Date: 2026-05-29

1. Introduction

This Privacy Policy explains what personal data deconta GmbH ("we", "us", "our", or "decoNXT") processes when you use the decoNXT mobile app, the decoNXT web dashboard, and the connected cloud services (together, the "Service"), why we process it, and the rights you have. decoNXT is used to set up, monitor, and control connected deconta devices on construction and abatement sites, such as negative-pressure measuring units (aircontrol, article 822) and air-sampling units (airsampler, article 861).

We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). The data controller responsible for processing is the entity named in the "Contact / Controller" section below.

2. Data We Collect

We collect only the data we need to operate the Service, keep your account secure, bill credit-based features, and deliver the device notifications you request. The categories below reflect what the Service actually stores.

Account and contact data

  • Email address: required to create and sign in to your account, for account-related communication, and for password resets.
  • Name: provided in your profile so device owners and administrators can identify you in shared-device user lists.
  • Phone number: optional. We only store it if you enable SMS or voice-call device notifications, and we use it solely to deliver those notifications.
  • Password: stored only as a salted cryptographic hash (bcrypt). We never store or have access to your plain-text password.
  • Billing information: optional company details you provide for invoicing, including company name, VAT ID, cost centre, billing email and phone number, billing address, and preferred invoice language. This information is stored with our payment processor Stripe and used by Stripe to issue your invoices; we do not store it in our own database.

Session and security data

  • For each active login session we store the device manufacturer, model, operating system and version, app version, IP address, user-agent string, an approximate location derived from your IP address, and session activity timestamps.
  • This lets you review and revoke your active sessions in the app, and helps us detect and prevent unauthorized access. Sessions expire automatically.

Billing and credit data

  • Your current credit balance, credit expiry date, and your auto top-up and low-credit-warning settings.
  • Payment and invoice records, including order amounts, service fees, taxes, applied discount codes, and references to the payment transaction. Card and payment details are handled by Stripe; we do not store full card numbers.

Device and usage data

  • Measurement readings and status uplinks sent by your connected devices, device error codes, and configuration changes you send, such as channel thresholds and operating settings.
  • Technical device network attributes reported by the hardware, for example device IP, MAC address, SIM identifier (ICCID), network signal, and time zone, the device location shown on the in-app map, and the list of users and permission levels for each device.
  • Diagnostic and access logs generated when you use the Service, used to operate, secure, and troubleshoot it.

Support-mode data

  • If you grant our support team access to your account or devices, we record the support session and an activity log of the actions taken. This creates an auditable record and protects both you and us.

3. Device Permissions

The mobile app requests the following device permissions:

  • Camera: used only to scan device QR codes when linking a device to your account. No photos or images are taken, transmitted, or stored.
  • Location: used only to display device locations on the map while you use the app. Your own location is not collected or stored.

4. Purpose of Processing

We process your data to:

  • Provide core functionality: account management, device setup, monitoring, configuration, groups, and reports.
  • Secure your account and detect, prevent, and investigate unauthorized access or abuse.
  • Deliver the device notifications you have enabled.
  • Process credit purchases, auto top-ups, invoices, and low-credit warnings.
  • Provide customer support and respond to your requests.
  • Maintain, troubleshoot, and improve the reliability and performance of the Service.
  • Comply with our legal and tax obligations.

5. Legal Bases for Processing

We rely on the following legal bases under Art. 6(1) GDPR:

  • Performance of a contract (Art. 6(1)(b)): creating and operating your account, managing devices, and delivering the features and notifications you use.
  • Consent (Art. 6(1)(a)): optional features such as SMS or voice-call notifications and the related storage of your phone number. You can withdraw consent at any time in the app settings.
  • Legitimate interests (Art. 6(1)(f)): securing the Service, preventing fraud and abuse, maintaining session and audit logs, and improving the Service.
  • Legal obligation (Art. 6(1)(c)): retaining invoices and transaction records as required by tax and commercial law.

6. Communication and Notification Preferences

Device notifications are disabled by default. You choose which channels to enable for each device, and you can change or disable them at any time in the app:

  • Email notifications.
  • SMS messages, which require a phone number and consume credits.
  • Voice calls, which require a phone number and consume credits.
  • Push notifications, where available.

We may also send you essential service and account messages, for example security, billing, and important changes, which are part of operating the Service.

7. Service Providers and Data Sharing

We do not sell your personal data. We share data only with service providers who help us run the Service, under appropriate data-processing agreements and, where data leaves the EU/EEA, appropriate safeguards such as the EU Standard Contractual Clauses. These include:

  • Payment processing: Stripe, to process credit purchases and auto top-ups and to issue invoices.
  • SMS and voice notifications: our messaging provider seven.io / sms77.io, to deliver the SMS and voice-call notifications you enable.
  • Maps: Google Maps, to render the in-app map that shows your device locations.
  • Hosting and infrastructure: our cloud and database providers, which store and process your data on our behalf.
  • Mobile connectivity: the mobile network operator providing the per-device SIM connectivity, through which devices communicate with our cloud over MQTT.
  • App distribution: Apple App Store and Google Play, when you install or update the app.

Other users you collaborate with on a shared device can see your name and email in that device's user and notification management, as needed for device administration. We may also disclose data where required by law.

8. Data Storage, Retention and Security

We use appropriate technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction, including encryption in transit, hashed passwords, access controls, and audited support access.

We retain personal data only as long as necessary for the purposes described above: account and device data for as long as your account exists, session logs for a limited period before automatic expiry, and invoices and transaction records for the periods required by law. When you delete your account, your personal data is deleted or anonymized, except where we must retain certain records to meet legal obligations. Unused credits are forfeited on account deletion; see the Terms of Service.

9. Your Rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data or completion of incomplete data.
  • Request erasure of your data.
  • Restrict or object to certain processing.
  • Receive your data in a portable format.
  • Withdraw consent at any time, without affecting processing already carried out.
  • Lodge a complaint with a data protection supervisory authority.

To exercise these rights, contact us using the details below. The competent supervisory authority for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte fuer Datenschutz und Informationsfreiheit Nordrhein-Westfalen).

10. International Transfers

Some of our service providers may process data outside the EU/EEA. Where this happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision to ensure your data remains protected.

11. Children

The Service is intended for professional use and is not directed to children. It is not intended for individuals under the age of 16. If you believe a child has provided us with personal data, please contact us so we can remove it.

12. Changes to This Policy

We may update this Privacy Policy to reflect changes to the Service or legal requirements. We will post the updated version here and update the effective date. Where required, we will notify you of material changes.

Contact / Controller

For privacy questions, to exercise your rights, or to file a complaint regarding the Service, please contact the data controller:

deconta GmbH

Im Geer 20

46419 Isselburg, Deutschland

Phone: +49 (0) 28 74 91 56 0

Email: info@deconta.com

Data Protection Officer

Fabio Pastars

Email: datenschutz@schauenburg.com