Privacy
PRIVACY
Information pursuant to Art. 13 GDPR. Version: 1 September 2026.
Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Dr. Alexander Mackensen
Wieslinger Weg 3
71116 Gärtringen
Germany
Email: hallo@gw4.me
Access data and server log files
When you visit this website, our provider automatically collects information about your visit and stores it in so-called server log files. This includes, in particular, browser type and version, operating system used, referrer URL, host name of the accessing computer, time of the server request and the IP address. This data is not assigned to specific persons. This data is not merged with other data sources.
Legal basis is Art. 6 (1) lit. f GDPR (legitimate interest in the technically error-free and secure operation of the website).
Contact enquiries
When you contact the provider (for example by contact form or email), the information provided will be stored for the purpose of handling the enquiry and in case follow-up questions arise. This data will not be shared without your consent.
Legal basis is Art. 6 (1) lit. b GDPR (contract initiation) or Art. 6 (1) lit. f GDPR (legitimate interest in responding to the enquiry).
Hosting
This website is hosted on the servers of an external provider. Personal data collected on this website is stored on the hoster's servers. The processing is carried out for the purpose of secure, fast and reliable operation of the website.
Legal basis is Art. 6 (1) lit. f GDPR. A data processing agreement pursuant to Art. 28 GDPR is in place with the hoster.
Contact form
The contact form on this website transmits nothing to us and nothing to anyone else. Your browser assembles the fields you fill in (name, email address, organisation if provided, message) into a prepared email draft and hands it to your own email program. There is no transfer to a service provider, no transfer to a third country and no storage on this website.
Your details are processed only once you send the message yourself and it arrives in our mailbox at our email provider. We use them solely to handle your enquiry and keep the correspondence for as long as this is necessary for handling it and for meeting statutory retention obligations.
Legal basis is Art. 6 (1) lit. b GDPR (contract initiation) or Art. 6 (1) lit. f GDPR (legitimate interest in answering enquiries). Until 26 August 2026 the form was operated through the service FormSubmit (Devro Labs, USA); that integration has been removed without replacement.
Account creation, password login and sign-in via email link
The standard login for the app app.gw4.me uses your email address and a password. We store your password exclusively in cryptographically hashed form (technical and organisational measure pursuant to Art. 32 GDPR); it is never stored or displayed in plain text. In addition, we offer sign-in via a one-time link that we send to you by email; this is a convenience option and is technically the same link as the confirmation link used during account creation. When you enter your email address on the sign-in page and request the email link, we process the following data:
- Email address — as the identifier of your account.
- IP address — to detect spam and to enforce the rate limit (3 requests per email/hour, 20 per IP/hour).
- Timestamp of the request and of the later use of the link — for security and audit purposes (single-use protection).
How your account is created: As soon as you submit your email address and it is not yet known to us, we create an as-yet-unconfirmed account (email as identifier, initially without a password). We send a confirmation link to that address. By clicking the link you demonstrate access to the mailbox, the account is deemed confirmed and you are signed in for the first time (double opt-in: the active entry and the active link click are the two confirmation steps). You then set a password of at least 12 characters, which completes account creation. A password must be set in order to sign in via the regular password page.
Storage period:
- Unconfirmed accounts (the confirmation link was never opened and no password was set) do not permit sign-in. They remain stored until deletion takes place; you may request deletion at any time, informally, at hallo@gw4.me (Art. 17 GDPR).
- Identifiers of links that have already been used are stored to prevent them from being used again.
- Active accounts remain in place until you request deletion or delete the account yourself.
Legal basis: Art. 6 (1) lit. b GDPR (contract initiation and performance) and Art. 6 (1) lit. f GDPR (legitimate interest in spam and abuse protection for the rate limits).
Security properties of the link: The confirmation and sign-in link is valid for 10 minutes, can be used only once and is HMAC-SHA-256 signed. A separately requested link to reset your password is valid for 1 hour for security reasons. If you lose access to the email mailbox on file, please contact hallo@gw4.me.
Email notifications
In your account at app.gw4.me you decide per occasion whether GRIDWORK gets in touch (system not reporting in, charging session failed, monthly report, product news). We store your choice per occasion and route, the time of your last decision and — for product news — the time of your consent. Delivery goes to the email address you confirmed.
Legal basis: Art. 6 (1) lit. b GDPR (operational messages as part of the service) and Art. 6 (1) lit. a GDPR (consent for product news, withdrawable at any time). Retention: until you change your choice or delete your account.
Browser messages (push notifications)
In addition to email you can have messages shown in your browser. This feature is optional and off by default. It only becomes active once you explicitly agree in your account and your browser then grants permission. There is no pre-ticked box.
What we store:
- The delivery address (endpoint) of your browser — the address the delivery service uses. It contains an identifier of your device or browser profile.
- Two subscription keys (
p256dhandauth) — we use them to encrypt the message content so the delivery service cannot read it. - Timestamps of setup, of your consent and of the last successful delivery.
We explicitly do not store a browser identifier (user agent), IP address or device name for this purpose — they are not required for delivery (Art. 5 (1) lit. c GDPR, data minimisation).
Purpose: solely to deliver the messages you selected. No audience measurement, no profiling and no advertising takes place over this route.
Recipients: The message is delivered via the push service of your browser's maker — depending on the browser Google (Firebase Cloud Messaging, Google Ireland Ltd./Google LLC), Mozilla (Mozilla Corporation), Apple (Apple Inc.) or Microsoft. That service learns the delivery address and the time; the content is encrypted for it (end-to-end per RFC 8291). Depending on the maker, a transfer to the USA may take place, based on standard contractual clauses or the EU-US Data Privacy Framework adequacy decision. The message content holds no personal data: only the occasion, a fixed message text and the link to your account are transmitted.
Retention: until you withdraw, at the latest until your account is deleted. If the delivery service reports that the subscription no longer exists (for example because you revoked permission in the browser or deleted the browser profile), we delete the entry automatically.
Withdrawal: at any time in your account under “Notifications” via the Withdraw and delete button. Withdrawal deletes the stored entry immediately and completely; it does not merely mute it. You can additionally revoke the permission in your browser settings. The lawfulness of processing carried out up to that point remains unaffected.
Legal basis: Art. 6 (1) lit. a GDPR (consent) and § 25 (1) TTDSG for accessing information on your device. Without your consent nothing is stored and nothing is delivered.
AI assistant in the app
Signed-in customers can use a chat assistant in the app app.gw4.me. It is built on a large language model. Using it is entirely optional: if you never open the chat, no data is processed along this route. Before you send your first message we tell you that you are writing to a machine, and an “AI” marker stays visible throughout the conversation (Art. 50 of Regulation (EU) 2024/1689, the AI Act).
Purpose: answering your questions about your account, your devices and charging optimisation. The assistant cannot change or switch anything on your installation — it has no access to the charging control. Safety questions, billing questions and faults you report are handed to a human; how your question reaches us in that case is described under “Retention” below. Detection works from a fixed list of keywords, not from understanding what you mean — so a question may be handed to a human even though you did not intend that. No automated decision with legal effect within the meaning of Art. 22 GDPR takes place.
What is sent to the language model provider:
- the text of your question,
- up to six earlier turns of the same conversation,
- excerpts from our knowledge base — general help texts, no customer data.
What is not sent: the readings of your installation shown on the dashboard (generation, surplus, state of charge, vehicle status), the list of your devices, your account name and your email address. That data is evaluated on our own server only.
What we strip from your text beforehand: email addresses, IBANs, phone numbers, street addresses, postcode and town, coordinates, vehicle registration numbers and your surname are replaced by fixed placeholders; those values never come back. Device identifiers are replaced by a numbered cover name ([GERAET-1]). The mapping exists only in memory for that single request and is written back into plain text in the answer — otherwise the assistant could not refer to your device by name.
Please note: this is a pattern filter, not anonymisation. Anything you write freely that does not match one of those patterns is passed on. Numeric readings such as kilowatt hours, kilowatts or percentages are deliberately left in plain text, because otherwise your question could not be answered. So please do not type anything into the chat that you would rather not have transmitted; for everything else you can reach us at hallo@gw4.me.
Recipient: our processor under Art. 28 GDPR is Anthropic Ireland, Limited, Dublin, Ireland — a company within the European Economic Area. Under the provider's terms of service, that entity is our contracting party for customers established in the EEA, not the US company. Processing may take place through subprocessors within the same group of companies, among them Anthropic PBC, San Francisco, USA, and through their infrastructure suppliers; a transfer to the USA therefore happens at that level (details in the next paragraph). The transfer is encrypted (TLS) and goes directly from our server to the provider's interface. One further recipient is added if your question is handed to a human: it then reaches our mailbox through our email provider, 1&1 IONOS SE, Montabaur, Germany (a processor under Art. 28 GDPR, servers in Germany). Details under “Retention” below.
Basis for the transfer to the USA: our processor is established in the EEA; the transfer to the USA happens at the level of subprocessing. For the USA there is no adequacy decision of the European Commission that we could rely on in that respect. The transfer is therefore based on the EU standard contractual clauses under Art. 46 (2) lit. c GDPR. We use the provider through a commercial access (interface/API). The provider's terms of service, which necessarily govern that use, incorporate a data processing agreement under Art. 28 GDPR; that agreement in turn incorporates the standard contractual clauses (Modules 2 and 3) and obliges the provider to bind its subprocessors to an equivalent level of protection and to remain liable for them. No separate signing step is provided for; the contract text is publicly available from the provider.
What remains open: our own assessment of the consequences of this transfer (transfer impact assessment) exists so far only as a draft and has not yet been signed — we will complete this by 31 December 2026. And regardless of that: even with the standard contractual clauses, access by US authorities to content processed by a subprocessor in the USA cannot be entirely ruled out under the law as it currently stands, and enforcing your rights in respect of processing in the USA may be harder than within the EU. We state this openly so that you can decide for yourself whether to use the assistant.
Retention:
- Record of the AI disclosure: as soon as you open the chat — that is, before your first message — we record in our security log that the notice about the use of AI was shown to you: the time, your account name, your customer identifier, the session identifier, an identifier of the notice text shown, and one truncated checksum each of your IP address and your browser identification. We do not store the IP address or the browser identification themselves, and the content of your conversation is not recorded there either. We keep this log for 12 months and then delete it.
- With us: the conversation is not stored permanently on our servers. We only record contentless metadata — time, account, where the answer came from and how many turns were involved, never the text of your message. It is different when your question is handed to a human (safety, billing, or a fault you have reported): in that case we send the text of your question — in the minimised form described above — together with your customer identifier by email to our own mailbox hallo@gw4.me so that a person can answer it. That email is held by our email provider (1&1 IONOS SE) and is kept for as long as we need it to handle your request and to meet statutory retention duties — it is therefore stored permanently, unlike the conversation itself. In addition we keep the minimised question as a fault hint in memory (at most 500 entries, visible to operations only, lost when the service restarts).
- In your browser: the visible history is kept in your browser's sessionStorage so that it survives navigating between pages. We clear it when you sign out; at the latest it is discarded when you close the browser tab. If you share a device with others, please close the tab once you are done.
- With the provider: the provider-side opt-out from storage (“zero data retention”) is not yet active. How long the provider keeps transmitted content therefore follows the provider's terms as in force at the time; we have not separately agreed any shorter period beyond that. The storage limitation applying there is the term of our agreement. Within 30 days of its end the provider must delete all customer data — including copies held by its subprocessors; excepted is data it must retain by law, needs to resolve a dispute with us, or needs to combat harmful use of the service (Section H of the data processing addendum, version of 24 February 2025). Whether and how the provider uses transmitted content to train its models likewise follows those terms; for the commercial access we use, the contract provides for processing only in order to deliver the service.
Objection and withdrawal: you can simply leave the assistant unused or close the window; nothing further is then transmitted. In so far as we rely on a legitimate interest, you may object to the processing at any time under Art. 21 GDPR — informally at hallo@gw4.me. Your other rights to information, rectification, erasure, restriction, data portability and to lodge a complaint with the supervisory authority remain unaffected; see the section Your rights.
Legal basis: Art. 6 (1) lit. b GDPR (customer support as part of the service owed); for protection against misuse and for capping cost additionally Art. 6 (1) lit. f GDPR (legitimate interest); for the record of the AI disclosure Art. 6 (1) lit. c GDPR in conjunction with Art. 50 of the AI Act, and Art. 6 (1) lit. f GDPR (secure operation). For the transfer to the USA see the paragraph “Basis for the transfer”. The disclosure of AI use follows Art. 50 of the AI Act. The assistant has been handling customer conversations through the provider named above since 13 June 2026.
Cookies
This website does not use tracking or analytics cookies, no audience measurement, no profiling services and no advertising networks. Only strictly necessary cookies are used, required for operating the login area (app.gw4.me):
- gw_session — session identifier, signed,
HttpOnly,SameSite=Lax, domain.gw4.me. Validity: session duration. - gw_role — role marker (
useroradmin) used solely to control the navigation (e.g. the admin menu).SameSite=Lax, domain.gw4.me. Contains no personal data. - gw-theme — stored locally (localStorage) for the chosen appearance (Sunrise / Moonrise), not transmitted as a cookie.
Legal basis: § 25 (2) No. 2 TTDSG (strictly necessary for the requested service) or Art. 6 (1) lit. f GDPR.
Encryption
This website uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content. An encrypted connection is indicated in the address bar of the browser.
Your rights
You have the right to free information about your stored personal data, its origin and recipients, and the purpose of the data processing (Art. 15 GDPR) as well as the right to rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), objection (Art. 21) and data portability (Art. 20). In addition, you have the right to lodge a complaint with the competent data protection supervisory authority.
Contact for privacy matters
For privacy-related enquiries please contact: hallo@gw4.me