Privacy Policy
How Voltnir B.V. collects, uses, and protects your personal data across the Voltnir marketing site and the customer portal, and the rights you have over it under the EU General Data Protection Regulation (GDPR).
This policy explains what personal data we process when you visit our website or use the Voltnir customer portal, why we process it, who we share it with, how long we keep it, and how you can exercise your rights. We keep it deliberately plain. Voltnir is a business-to-business product, and we collect only what we need to provide it.
1 · Who we are
The data controller responsible for your personal data is:
- Voltnir B.V.
- Registered office: Salland 1, 1948 RE Beverwijk, Netherlands
- Chamber of Commerce (KvK): 42141121
- Contact for privacy matters: legal@voltnir.io
Voltnir B.V. is established in the Netherlands. We have not appointed a statutory Data Protection Officer, as we are not required to; privacy questions are handled by the contact above.
2 · What we collect & why
We collect personal data that you provide directly (when you register, manage your account, license the software, or contact support) and a limited amount that is generated automatically when you use the portal (such as security logs). We do not buy or sell personal data, build advertising profiles, or track you across other websites.
| Category | What it includes | Why we process it |
|---|---|---|
| Account & identity | Email address, password (stored only as a salted hash, so we never see it), company name, contact name, job role, and country. | To create and secure your account, authenticate you, and provide the portal. |
| Consent records | Your acceptance of these terms (the version accepted and when), and whether you have opted in to product-update and marketing emails, with the date and time you opted in. | To record that you agreed to our terms, and to keep an auditable record of whether you consent to receive product-update and marketing emails, so that any such emails go only to people who have opted in. The marketing opt-in is optional and you can change or withdraw it at any time. |
| Billing & company | VAT number, company registration number, and billing address; invoice records (amount, currency, status). | To issue licences and invoices and to meet our accounting and tax obligations. |
| Licensing | Licence keys, the legal entity a licence is issued to, licence type and environment, and the EPEX SPOT market identifiers (account/user IDs) tied to your entitlements. | To issue, sign, and manage the software licences you hold. |
| Security & audit logs | A record of security- and account-relevant events (sign-in, password and email changes, licence reveals and downloads, etc.), each stored with your IP address, the browser or device you were using (its user-agent string), and a timestamp. We also keep the time and IP address of your most recent sign-in on your account. | To keep the service secure, detect and investigate abuse, and maintain an auditable record. We deliberately redact passwords, tokens, and keys from these logs. |
| Support | The subject and body of support tickets and any files you attach, plus our replies. Opening a ticket sends its contents by email to our support inbox (support@voltnir.io); we don't route it through any other tool or service. | To answer your questions and provide support. Please don't include sensitive personal data in a ticket; it isn't needed. |
| Technical & usage | The strictly-necessary cookies described in section 4, standard server logs, and a record of portal usage events (page/action, IP address, and browser user-agent string). | To keep you signed in, protect forms against cross-site request forgery, operate the site securely, and troubleshoot issues. |
3 · Legal bases
Under the GDPR we rely on the following legal bases (Article 6):
- Performance of a contract: to provide your account, the portal, and the licences you take out (account, licensing, billing, and support data).
- Legal obligation: to retain invoices and accounting records for the period required by Dutch and EU law.
- Legitimate interests: to keep the service and our customers secure and to prevent abuse (security and audit logs, portal usage events). We have weighed these interests against your rights and use the minimum data necessary.
- Consent: where we ask for it explicitly — currently, your optional consent to receive product-update and marketing emails, which you can withdraw at any time. We do not use any cookies or tracking that require consent (see section 4).
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects (Article 22).
4 · Cookies
We use only strictly-necessary cookies: the kind that, under the ePrivacy rules, do not require a consent banner because the service cannot function without them. We do not use advertising or tracking cookies. For website statistics we use a privacy-friendly, cookieless analytics tool (see section 5) that sets no cookies and collects no personal data, so it too needs no consent banner. We host our own fonts; apart from that analytics tool, loading a page sends your data to no third party.
| Cookie | Purpose | Lifetime |
|---|---|---|
VOLTNIR_SESSION | Keeps you signed in during a visit and protects forms. | Until you close your browser. |
REMEMBERME | Set only if you tick “remember me” at sign-in, so you stay signed in between visits. | 30 days. |
| CSRF token | Protects forms against cross-site request forgery. | Per session / request. |
5 · Who we share your data with
We do not sell your personal data and we do not share it for anyone else's marketing. We share it only with the service providers that help us run Voltnir, each acting as our processor under a data-processing agreement, and only as far as needed:
- Hosting: our servers are operated by TransIP, who host the application and database on our behalf under a signed data processing agreement.
- Email delivery: transactional emails (verification, password reset, email-change confirmations, and support notifications) are sent through Mailgun (Sinch), under Sinch's Data Processing Agreement, with Standard Contractual Clauses in place for any transfer outside the EEA. These emails go only to your own address (or, for an email change, to the old and new addresses).
- Website analytics: we use Simple Analytics to measure aggregate traffic to our public website. It is cookieless, collects no personal data and no cross-site identifiers, does not track you across other sites, and stores its data in the EU. It runs on the pages anyone can reach without signing in — the marketing site and the sign-in, registration and related account-access pages — but not inside the authenticated portal once you have signed in.
We do not push account, licensing, or support data to any other internal or third-party tool, service, or webhook.
We may also disclose data where we are legally required to (for example, in response to a valid request from a competent authority), or to establish, exercise, or defend legal claims.
6 · International transfers
We host and process your data within the European Union / European Economic Area. Where a processor we use is located outside the EEA, that transfer is protected by an adequacy decision or by the European Commission's Standard Contractual Clauses.
7 · How long we keep your data
We keep personal data only for as long as we need it for the purposes above, and enforce these periods automatically:
- Account, licensing & support data: for as long as your account is active, and then anonymised within 90 days of account closure, unless we must keep it longer by law.
- Consent records (your terms acceptance and marketing-email preference): kept while your account is active, and afterwards retained only as a minimal record of the consent that was given — no longer linked to you once your account is anonymised.
- Invoices & accounting records: retained for at least 7 years, as Dutch tax law requires. We never delete an invoice's identifying details before that floor, even if the related account has been closed and anonymised.
- Security & audit logs: retained for 24 months, after which they are deleted, except where an ongoing security or legal matter requires us to keep them (a documented legal hold).
- Portal usage events: retained for 12 months, then deleted.
- Password-reset tokens: deleted as soon as they expire.
8 · Your rights
Under the GDPR you have the right to:
- Access: get a copy of the personal data we hold about you.
- Rectification: correct data that is inaccurate or incomplete (much of it you can edit yourself in the portal).
- Erasure: ask us to delete your data, where we have no overriding obligation to keep it. You can close your account yourself at any time from the portal's account settings; this immediately ends your access and starts the 90-day anonymisation described in section 7.
- Restriction: ask us to limit how we use your data.
- Portability: receive the data you gave us in a structured, machine-readable format.
- Objection: object to processing we carry out on the basis of legitimate interests.
- Withdraw consent: where we rely on consent, withdraw it at any time, without affecting earlier processing.
To exercise any of these, email legal@voltnir.io. We will respond within one month. You also have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens, or with the supervisory authority in your country of residence.
9 · How we protect your data
Security is built into the product. Among other measures: passwords are stored only as strong salted hashes; all traffic is served over HTTPS with HSTS; the site enforces a strict Content-Security-Policy that permits only our own resources and our cookieless analytics provider; access to the portal is gated and role-based; and security-relevant events are audit-logged with secrets redacted. No system is perfectly secure, but we work to protect your data in line with the GDPR's “appropriate technical and organisational measures”.
10 · Children
Voltnir is a professional product for businesses and is not directed at children, and account holders must be at least 18 (see our Terms of Use). We do not knowingly collect personal data from anyone under 18.
11 · Changes to this policy
We may update this policy from time to time. When we make a material change we will update the “last updated” date above and, where appropriate, notify you. The current version is always available at this page.
12 · Contact
Questions about this policy or your personal data? Email legal@voltnir.io or write to Voltnir B.V. at the address in section 1.