Privacy policy
Privacy Policy
Effective date: 28 July 2026
Last updated: 28 July 2026
Version: 1.0
This Privacy Policy explains how S.C. Codershyve S.R.L. handles personal data in connection with our online store, the SunGrid Portal software, the SunGrid Portal mobile application, and our licensing and support services. It is written to be accurate to how these products actually work, rather than to describe processing we do not carry out.
Please read Section 3 first. It sets out who is responsible for which data, and it is the single most important part of this Policy for understanding your rights and whom to contact.
1. Who we are
| Controller | S.C. CODERSHYVE S.R.L. (“Codershyve”, “we”, “us”, “our”) |
| Registered office | Str. Motorului nr. 5A, ap. 30, Baia Mare, Maramureș 430013, Romania |
| Trade Register no. / EUID | J2024001049242 / ROONRC.J2024001049242 |
| Sole registration code / VAT ID | 50327689 / RO50327689 |
| Privacy contact | office@codershyve.com |
| Telephone | +40 770 533 094 |
| Websites | sungrid-portal.io · codershyve.com · codeops.ro |
We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of Regulation (EU) 2016/679 (“GDPR”). Privacy enquiries are handled at the address above.
2. What this Policy covers
This Policy covers, together the “Services”:
- the Store and our websites — our online shop at sungrid-portal.io, hosted on Shopify, through which Licences, Subscriptions and Technical Support are sold, together with our corporate and documentation websites at codershyve.com and codeops.ro;
- the Web Portal — the SunGrid Portal web application and its backend services, deployed on infrastructure operated by you or your organisation;
-
the Mobile App — the SunGrid Portal application for Android and iOS, package
com.bolchisb.SungridPortal, published by Codershyve; - Licensing and Support — licence activation, entitlement management, image-update entitlements, and the consent-based remote support facility.
This Policy does not cover third-party products you connect to SunGrid Portal, such as inverters, gateways, device clouds or energy-price providers. Those are governed by their own privacy policies.
3. Who is responsible for which data — controller and processor roles
SunGrid Portal is self-hosted software. We do not operate a central cloud that aggregates customer data across installations, and in the ordinary course we have no access to the data inside your installation.
| Data | Controller | Our role |
| Store orders, billing, invoices, customer support correspondence | Codershyve | Controller — Sections 4 and 5 apply in full |
| Portal user accounts, telemetry, installations, automations, notes, audit logs inside your deployment | You or your organisation (the operator of the deployment) | Not a controller and, in normal operation, not a processor — we have no access. See Section 6 |
| Data on your phone or tablet in the Mobile App | Stays on your device; the backend you connect to is controlled by its operator | No access. See Section 7 |
| Licence records, installation identifiers, hardware fingerprints, entitlement state | Codershyve | Controller. See Section 8 |
| Content accessed during a remote support session you have opened | You or your organisation | Processor, acting on your instructions. See Section 9 |
What this means in practice. If you are an end user of a SunGrid Portal installation operated by your employer, your installer or an energy service company, and you wish to exercise your data protection rights over the data inside that installation, your request must be addressed to that operator, not to us. If you contact us instead, we will tell you so and, where we can, point you in the right direction; we cannot access, produce, correct or erase data held in an installation we do not operate.
4. The Store — what we collect when you buy from us
4.1 Categories of data
- Identity and contact data: name, e-mail address, telephone number where you provide it, and for business buyers the company name, registered address and VAT identification number.
- Order and billing data: items purchased, price, currency, order number, invoice details, tax status, purchase history, and the two consents recorded at checkout under Section 18 of our Return and Refund Policy, with their timestamp and policy version.
- Payment data: we do not receive or store full card numbers. Payments are processed by Shopify and its payment providers. We receive only the transaction result, the payment method type, the last digits of the instrument and the authorisation reference.
- Delivery data: the e-mail address to which licence keys, activation tokens and access credentials are sent, and records of that delivery.
- Technical data generated by the Store: IP address, browser and device type, pages viewed, referring page, and cookie identifiers, as described in Section 12.
- Correspondence: support, refund, complaint and warranty communications, and any information you choose to include in them.
4.2 Purposes and legal bases
| Purpose | Legal basis (GDPR Art. 6) |
| Concluding and performing your purchase; delivering Licences and access; providing Subscriptions and Technical Support | Art. 6(1)(b) — performance of a contract |
| Handling refunds, withdrawals, complaints and warranty claims | Art. 6(1)(b) and Art. 6(1)(c) — contract and legal obligation |
| Invoicing, accounting, tax and VAT reporting, statutory record keeping | Art. 6(1)(c) — legal obligation |
| Retaining checkout consent records as evidence in refund, chargeback or dispute proceedings | Art. 6(1)(c) and Art. 6(1)(f) — legal obligation and our legitimate interest in establishing and defending legal claims |
| Preventing fraud, abuse of the refund policy, licence tampering and unauthorised redistribution | Art. 6(1)(f) — legitimate interest in protecting our business |
| Store security, availability and abuse prevention | Art. 6(1)(f) — legitimate interest |
| Sending service messages about your order, licence or security matters | Art. 6(1)(b) — performance of a contract |
| Non-essential cookies and analytics on the Store | Art. 6(1)(a) — consent, withdrawable at any time |
| Marketing e-mail to existing customers about similar products | Art. 6(1)(f), with an unsubscribe link in every message; consent where required by local law |
4.3 Is providing data mandatory?
Identity, contact, billing and delivery data are necessary to conclude and perform the contract. If you do not provide them we cannot process your order or issue a valid invoice. Everything else is optional.
5. Store retention periods
| Data | Retention |
| Invoices and accounting records | 10 years from the end of the financial year, as required by Romanian Accounting Law no. 82/1991 |
| Order records and checkout consent records | 3 years from the end of the contract, extended to cover any pending claim, in line with the general limitation period under Article 2517 of the Romanian Civil Code |
| Licence and entitlement records | For the life of the Licence, plus 3 years |
| Support and complaint correspondence | 3 years from the last message |
| Marketing contact data | Until you unsubscribe or object, then suppression-list only |
| Store server logs and security logs | Up to 12 months |
6. The Web Portal — software you run yourself
6.1 We are not the controller of your installation data
The Web Portal runs on infrastructure that you or your organisation operate. Its databases, telemetry stores, logs and backups are yours. We do not receive copies of them, and we cannot access them except during a remote support session that you have expressly opened (Section 9).
6.2 What the software processes, so you can meet your own obligations
We set out below what the software processes, so that you as operator can complete your own record of processing activities under Article 30 GDPR and inform your own users. All of the following is stored in your deployment:
- Portal accounts: user identifier, name, e-mail address, role (administrator, installer or user), the locations a user is assigned to, credential material, and account timestamps.
- Sessions: refresh-token hashes, session creation and expiry times, revocation state, and the IP address, user agent and device name associated with a session.
- Audit events: event type, severity, originating service, acting user and role, acting IP address and user agent, location, portal, device, resource and a summary. The IP address and user agent fields are encrypted at rest.
- Installation and asset data: site names, geographic coordinates of installations, equipment inventories, single-line diagrams, string configurations and topology.
- Operational and telemetry data: readings from inverters, batteries, meters, gateways and controllers, alarms, automation rules and their execution history, forecasts, tariff calendars and energy accounting.
- User-generated content: notes, attachments, dashboards and widget configurations.
- Notification settings: recipient addresses and channel configuration for e-mail, Telegram, webhook, Apprise and push notifications.
Telemetry readings describe equipment rather than people. Be aware, however, that in a residential or single-occupant installation, consumption and production patterns can reveal occupancy and household routines and should therefore be treated as personal data by the operator.
6.3 Security measures built into the software
- Sensitive data is encrypted at rest; metrics and telemetry are exempt from that requirement.
- Authentication uses an
HttpOnlysession cookie withSameSite=Lax, so the session token is not readable by page scripts. - Access is governed by a role model with three roles, and installer access can be scoped to specific locations.
- Production images use FIPS 140-3 validated cryptography.
- Backend services communicate over mutual TLS where they cross a trust boundary.
- Actions that change configuration are recorded in the audit log.
Configuring these correctly, keeping the deployment patched, controlling who has accounts, and securing the underlying host and network remain the operator's responsibility.
7. The Mobile App
7.1 The app is a client, not a service
The Mobile App does not operate a service of its own. It connects to a backend whose address you enter or scan on the sign-in screen. That backend, and the data it holds, is operated by you or your organisation. We do not receive your energy data, your account data or your credentials.
7.2 What is stored on your device
The following is held in the app's private storage inside the operating system sandbox, and on no server we control:
- the backend address and connection protocol;
- the e-mail address last used to sign in, to pre-fill the form;
- the access token, the refresh token and their expiry time;
- the selected interface language.
Your password is not stored on the device. It is sent directly to the backend you configured, to authenticate you, and nowhere else. Signing out or uninstalling the app removes everything listed above.
7.3 Device permissions and why they exist
| Permission | Why |
| Camera | Only to scan a QR code on the sign-in screen, which fills in the server address and credentials. No photo or video is captured, stored or transmitted. The permission is optional; you can type the details in manually. |
| Microphone / record audio | Declared only as a dependency of the camera component. The app never records, uses or transmits audio. |
| Network state, Wi‑Fi state, multicast | To discover a SunGrid Portal server on your local network by mDNS, so you can connect to it. This does not collect browsing activity. |
The app does not request device location, contacts, calendar, photo library, SMS or call data.
7.4 What the app does not do
- No advertising, and no advertising identifiers.
- No third-party analytics, tracking or crash-reporting SDKs.
- No sale or sharing of personal data with data brokers.
- No profiling and no automated decision-making producing legal or similarly significant effects.
7.5 App distribution and updates
The app is built and distributed using Expo Application Services and may contact the Expo update service to download over-the-air JavaScript updates. That mechanism delivers updates only; it is not used to collect your energy or account data. Distribution through Google Play and, where applicable, the Apple App Store is subject to those stores' own privacy policies. Push notifications, where you enable them, are delivered through Firebase Cloud Messaging and, on Apple devices, the Apple Push Notification service.
8. Licensing, activation and image entitlements
Where your installation is licensed by us, the licence client running in your deployment communicates with our licence server. For this we act as controller, and we process:
- An installation identifier assigned by us on first contact.
- A hardware fingerprint — a one-way SHA-256 hash derived from stable machine characteristics such as the machine identifier, product and board serial numbers, processor information and host name. We store the hash, which binds the licence to one machine. The hash cannot be reversed to reveal the underlying values.
- Licence and entitlement state — status, validity period, feature and image-update entitlements, and the image manifest applicable to your installation.
- Connection metadata — the time of each check-in and the client version, used to determine whether a licence is active and to detect tampering or duplication.
The legal basis is Article 6(1)(b), performance of the licence contract, and Article 6(1)(f), our legitimate interest in preventing unlicensed use, duplication and circumvention of licence enforcement. Communication uses mutual TLS with a pinned certificate. We do not receive telemetry, user accounts or installation data through this channel.
9. Remote support sessions
We offer a remote support facility. It is important that you understand exactly how it works.
- A session can only be initiated from your side, by someone with access to your installation running the support client. We cannot open one, and we cannot connect to an installation that has not opened a session.
- While a session is open, an operator on our side can run commands and read and write files on that machine, with root privileges. This is necessary for diagnosis and repair, and it means the operator may see any data present on that machine, including personal data held in your deployment.
- For this processing we act as your processor under Article 28 GDPR. We act only on your instructions, only for the purpose of the support you requested, and we do not retain copies of your data beyond what is necessary to resolve the issue and to record what was done.
- The session ends when you close it. We recommend that you close it as soon as the work is finished, that you supervise it, and that you treat opening a session as granting privileged access.
If your organisation requires a written data processing agreement before using this facility, contact us at office@codershyve.com and we will put one in place.
10. Artificial intelligence features
Where AI-assisted features are enabled in a deployment — such as the conversational assistant, automation authoring from natural language, chart suggestions and note summarisation — the text of the prompt, together with the contextual data needed to answer it, such as available telemetry paths, device names and configuration fragments, is sent to a third-party large language model provider (Google, Gemini model family) for processing.
- These features are optional and are configured by the operator of the deployment. Where they are not configured, no data is sent.
- Do not enter personal data, credentials or confidential information into AI prompts unless the operator has satisfied itself that doing so is lawful and appropriate.
- The operator of the deployment is the controller for this processing and is responsible for the lawful basis, for informing its own users, and for the terms agreed with the AI provider under the API credentials it configures.
- No automated decision producing legal or similarly significant effects for an individual is taken by these features. Automation rules generated with AI assistance require human review and activation.
11. Recipients and third parties
We do not sell personal data. We do not share it with data brokers. We do not use it for advertising or cross-context behavioural profiling.
Personal data is disclosed only to the following categories of recipient:
| Recipient | Purpose | Applies to |
| Shopify | Hosting the Store, order processing, checkout, payment orchestration | Store |
| Payment providers engaged through Shopify | Taking payment, fraud screening, chargeback handling | Store |
| Accountants, auditors, tax authorities | Statutory accounting and tax obligations | Store |
| Expo Application Services | Building and delivering mobile app updates | Mobile App |
| Google Play, Apple App Store, Firebase Cloud Messaging, Apple Push Notification service | App distribution and push notification delivery | Mobile App |
| Google (Gemini) | AI-assisted features, where enabled by the operator | Web Portal, configured by the operator |
| Tuya Cloud and eWeLink / CoolKit | Controlling smart devices you have linked, where you configure such a link | Web Portal, configured by the operator |
| PVGIS, operated by the Joint Research Centre of the European Commission | Solar irradiance and production forecasts for the coordinates of an installation | Web Portal |
| OpenStreetMap | Displaying installation maps | Web Portal |
| Notification channels you configure — e-mail servers, Telegram, webhooks, Apprise | Delivering alerts you have asked for | Web Portal, configured by the operator |
| Professional advisers, insurers, courts and competent authorities | Establishing, exercising or defending legal claims, and complying with legal obligations | All |
| An acquirer, in a merger, acquisition or transfer of business | Continuity of the contract, subject to this Policy continuing to apply | All |
Recipients marked “configured by the operator” receive data only because the operator of a deployment has chosen to enable that integration and has supplied the credentials for it. In those cases the operator, not Codershyve, decides the purpose of the disclosure.
12. Cookies and local storage
12.1 The Store and our websites
The Store runs on Shopify and uses cookies that are strictly necessary to operate the shop — maintaining your cart, securing the checkout, load balancing and fraud prevention. These are set on the basis of Article 6(1)(f) and do not require consent under Article 82 of Romanian Law no. 506/2004. Any analytics or marketing cookies are set only with your consent, which you may give or refuse in the cookie banner and withdraw at any time. Refusing them does not prevent you from purchasing.
12.2 The Web Portal
The Web Portal uses:
- a session cookie that is
HttpOnlyandSameSite=Lax, strictly necessary to keep you signed in; - browser local storage for interface preferences only — the active location, the current user identifier used to scope the interface, and dashboard and panel preferences.
The Web Portal contains no advertising cookies and no third-party tracking cookies.
12.3 The Mobile App
The Mobile App uses no cookies. It stores only the items listed in Section 7.2, in the operating system's application sandbox.
13. International transfers
Our own processing takes place in Romania and the European Union. Some recipients listed in Section 11 — in particular Shopify, Google, Expo, Apple and the device-cloud providers — may process data outside the European Economic Area, including in the United States.
Where that happens, the transfer is made on the basis of an adequacy decision of the European Commission where one applies, or otherwise on the basis of Standard Contractual Clauses adopted under Article 46(2)(c) GDPR, supplemented where appropriate by additional technical and organisational measures. You may request further information, and a copy of the relevant safeguards, at office@codershyve.com.
Where a deployment operator enables an integration whose provider is located outside the EEA, the operator is responsible for the lawfulness of that transfer.
14. Security
We apply technical and organisational measures appropriate to the risk, including encryption of sensitive data at rest, TLS in transit, mutual TLS between services that cross a trust boundary, FIPS 140-3 validated cryptography in production images, role-based access control, least-privilege administrative access, audit logging of configuration changes, and hardened container images that are scanned for known vulnerabilities.
No system is completely secure. We design the Services to hold as little personal data as possible, and to keep customer operational data inside the customer's own infrastructure rather than in a central store of ours.
Where we are the controller and a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours under Article 33 GDPR and, where the risk is high, notify you under Article 34. For a breach inside a self-hosted deployment, the notification obligation falls on the operator of that deployment, since it is the controller; we will assist as required by Article 28(3)(f) where we act as processor.
15. Your rights
Subject to the conditions and exceptions in the GDPR, you have the right to:
- access your personal data and obtain a copy (Art. 15);
- rectification of inaccurate or incomplete data (Art. 16);
- erasure, where one of the grounds in Article 17 applies. Note that we cannot erase data we must keep for accounting and tax purposes until the statutory period expires;
- restriction of processing (Art. 18);
- data portability for data processed by automated means on the basis of contract or consent (Art. 20);
- object at any time to processing based on legitimate interests, including profiling (Art. 21), and absolutely to processing for direct marketing;
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3));
- not be subject to a decision based solely on automated processing producing legal or similarly significant effects (Art. 22). We take no such decisions.
15.1 How to exercise them
Write to office@codershyve.com. We respond within one month, extendable by two further months for complex or numerous requests, in which case we will tell you within the first month and explain why. Exercising your rights is free of charge; we may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive, in particular because it is repetitive (Art. 12(5)). We may ask for information reasonably necessary to confirm your identity before acting.
15.2 Requests about data inside a deployment
Please re-read Section 3. If your request concerns data held inside a SunGrid Portal installation operated by someone else, address it to that operator. We have no access to it and cannot act on your request.
15.3 Complaints
You may lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement (Art. 77). The Romanian authority is:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru nr. 28–30, Sector 1, 010336 București, Romania
www.dataprotection.ro · anspdcp@dataprotection.ro
You also have the right to an effective judicial remedy under Articles 78 and 79 GDPR. We would appreciate the chance to address your concern first.
16. Children
The Services are technical tools for operators of energy installations and are not directed at children. We do not knowingly collect personal data from a child under 16, or under the lower age set by the Member State concerned, which in Romania is 16 under Article 8 GDPR as applied nationally. If you believe a child has provided us with personal data, contact us and we will delete it.
17. Automated decision-making and profiling
We do not carry out profiling, and we take no decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 GDPR. Automation and optimisation features inside the Web Portal act on equipment according to rules configured by the operator; they do not evaluate individuals.
18. Jurisdiction-specific information
18.1 United Kingdom
Where the UK GDPR and the Data Protection Act 2018 apply, this Policy is to be read accordingly, and you may complain to the Information Commissioner's Office at ico.org.uk.
18.2 California and other US states
We do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are used in the California Consumer Privacy Act as amended. We do not knowingly collect the personal information of consumers under 16 for such purposes. Where applicable state law grants you rights to know, delete, correct, or opt out, you may exercise them at office@codershyve.com, and we will not discriminate against you for doing so.
18.3 Switzerland
Where the Swiss Federal Act on Data Protection applies, references to the GDPR are to be read as references to the corresponding provisions of that Act, and you may contact the Federal Data Protection and Information Commissioner.
19. Changes to this Policy
We may update this Policy as the Services evolve or as the law changes. The version in force is the one published here, and the effective date at the top reflects the latest revision. Where a change materially affects how we process your personal data, we will give you notice by a prominent notice in the Services or by e-mail before it takes effect.
20. Contact
S.C. CODERSHYVE S.R.L.
Str. Motorului nr. 5A, ap. 30, Baia Mare, Maramureș 430013, Romania
Trade Register no. J2024001049242 · EUID ROONRC.J2024001049242
Sole registration code 50327689 · VAT RO50327689
Privacy contact: office@codershyve.com · Telephone: +40 770 533 094
Websites: sungrid-portal.io · codershyve.com · codeops.ro
This Policy is an information notice under Articles 13 and 14 GDPR. It does not constitute legal advice to you, and it does not replace the privacy notice that an operator of a SunGrid Portal deployment must give to its own users.







