Thank you for your interest in our smart home system Homematic IP. The protection of your personal data during collection, processing and use when using Homematic IP is important to us.
Below you will find information about which data is collected during your use of Homematic IP and how it is used. This data protection notice only applies to the use of Homematic IP and the linking of Homematic IP with the IoT platform Home Connect Plus.
I. Contact and your rights
1. Name and address of the person responsible
The responsible party within the meaning of the General Data Protection Regulation and other national data protection laws of the Member States as well as other data protection provisions applicable to us is:
2. Name and address of the data protection officer
Lawyer Heiko Janssen
Janssen & Enninga Notar und Rechtsanwälte
Julianenburger Str. 19
3. Your rights
You are entitled to assert your rights as a data subject against us at any time. If the respective legal requirements are met, this includes the following rights:
3.1 Right to information according to Art. 15 DSGVO
You have the right at any time to free information about your personal data stored by us. In addition, you have the right at any time to have your data provided to us transferred to you or to a third party.
You have the right to request information about whether the personal data concerning you is transferred to a third country or to an international organization. In this context, you may request to be informed about the appropriate safeguards pursuant to Art. 46 DSGO in connection with the transfer.
If you wish to receive information, please contact us in writing at firstname.lastname@example.org.
Please note that we can only transfer data based on consent or a contract.
3.2 Right to correct inaccurate data or to complete data according to Art. 16 DSGVO
We will correct data stored about you at your request, provided that other legal regulations (such as the obligations to retain data under the German Commercial Code) do not prevent this.
If you wish to have your data corrected, please contact us in writing at email@example.com.
3.3 Right to deletion according to Art. 17 DSGVO
We will delete data stored about you at your request, provided that other statutory provisions (such as the obligations to retain data under the German Commercial Code) do not prevent this.
If you wish your data to be deleted, please contact us in writing at firstname.lastname@example.org.
3.4 Right to restriction of processing pursuant to Art. 18 DSGVO
Under the following conditions, you may request the restriction of the processing of personal data concerning you:
(a) If you contest the accuracy of the personal data concerning you for the period of time necessary to enable the controller to verify the accuracy of the personal data.
b) The processing is unlawful and you object to the erasure of the personal data and request instead the restriction of the use of the personal data
c) The controller no longer needs the personal data for the purposes of processing, but you need it for the assertion, exercise or defense of legal claims; or
d) If you have objected to the processing pursuant to Article 21 (1) DSGVO and it has not yet been determined whether the controller's legitimate grounds override your grounds.
If the processing of personal data relating to you has been restricted, such data may - apart from being stored - only be processed with your consent or for the assertion, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or another Member State.
3.5 Right to data portability according to Art. 20 DSVGO
You have the right to have the data you have provided to us transferred to a third party at any time.
If you wish to obtain information, please contact us in writing at email@example.com.
Please note that we can only transfer data based on consent or a contract.
3.6 Right to complain to the supervisory authority pursuant to Art. 13 para. 2 lit. d) DSGVO
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, workplace or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
The supervisory authority to which the complaint has been lodged shall inform the complainant of the status and outcome of the complaint, including the possibility of a judicial remedy under Article 78 GDPR.
II. General information on data processing
1. Personal data
Personal data is information such as name, address or e-mail address that can be directly assigned to your person.
2. Data collection and storage
a) The Homematic IP range includes numerous products from the areas of indoor climate, security and light & shade. Here, the individual components, such as radiator thermostats, dimming actuators, etc., are linked to the Homematic IP Access Point. With the help of the Homematic IP app, you can then control the components individually. The configuration of the individual devices is handled by the Homematic IP cloud service, which is operated exclusively on German servers of eQ-3 AG and is therefore subject to both European and German data protection guidelines.
During configuration and operation of the Homematic IP system, the following data is collected and stored:
- Serial number, as well as properties necessary for operation such as firmware version of the Homematic IP access point.
- Serial number, name, model designation, firmware version as well as device configurations made by the user
- Room designations and assignment of device to room
- Device model and operating system version of the smartphones used
- First and last connection time of a smartphone
- Configuration of the function modules (light & shade, room climate, security, automation)
For the "measurement data acquisition" function, it is necessary that status values of a device (e.g. current power of a switching measurement actuator) are stored over a longer period of time. The user defines in the smartphone app himself for which devices "measurement data" are stored. If the user has not selected anything, no data will be stored.
When using and operating the Homematic IP system without linking it to the IoT platform Home Connect Plus, this data is used exclusively on servers of eQ-3 AG in Germany for the technical implementation of the Homematic IP system. In principle, the data is not passed on to third parties. If you yourself have connected Homematic IP with other services (such as Amazon Alexa or Google Assistant), a transfer to these services will take place. Your data will not be personalized.
b) You can additionally link your Homematic IP smart home system with the IoT platform Home Connect Plus, operated by Residential IoT Services GmbH.
To link Homematic IP with the IoT platform Home Connect Plus, a temporary (i.e., effective for a limited time) activation key is required, which can be generated in the Homematic IP app. After successful activation, an individual authentication key is assigned, which can be used to retrieve certain data from Residential IoT Services GmbH when using the Home Connect Plus IoT platform to implement the control commands you use. In doing so, the following data will be forwarded to Residential IoT Services GmbH:
- Serial number of the Homematic IP access point
- Serial number / room name of all devices linked to Homematic IP
- Description of the respective device
- Manufacturer name of the respective device
- Model name of the respective device
- Version number of the respective device
- Control commands and status values supported by the devices
- Status information of the respective device (e.g. set temperature of the radiator thermostat / room)
- Current accessibility status of the devices
The data is forwarded by eQ-3 AG to Residential IoT Services GmbH in a non-personalized form. However, it is possible that Residential IoT Services GmbH itself collects the data received via both services by linking the IoT platform Home Connect Plus with Homematic IP in accordance with the Residential IoT Services GmbH data protection notices (https://www.home-connect-plus.com/de/datenschutz.html).
c) When linked with Home Connect Plus (according to 1b), the proactive transmission of device states to Home Connect Plus is supported by the Homematic IP system for the use of Homematic IP devices in Home Connect Plus. For this purpose, it is necessary that the relevant status values of a device are transmitted to Residential IoT Services GmbH whenever the status of the devices changes. The status values are, for example:
- The switching status of switching actuators
- brightness values of dimming actuators
- setpoint and actual temperature of heating groups or rooms
- the accessibility status of the devices
The user defines in the smartphone app itself whether additional status data is transmitted. This function can be deactivated in the Home Connect Plus settings in the Homematic IP app. If this function is deactivated, no data is transmitted proactively.
3. Processing and use of personal and other data
The data collected under clause II.2a is collected exclusively in non-personalized form for the operation of Homematic IP.
The data collected under clauses II.2b and 2c will be forwarded exclusively in non-personalized form by eQ-3 AG to Residential IoT Services GmbH for the implementation of control commands related to you if you use the IoT platform Home Connect Plus. eQ-3 AG does not receive any evaluation from Residential IoT Services GmbH about the data collected by Residential IoT Services GmbH.
4. Objection / right to information
If you do not want your data to be forwarded to Residential IoT Services GmbH in accordance with section II.2b, you must revoke access to Homematic IP in the Home Connect Plus app. In this case, the authentication key would expire and Residential IoT Services GmbH would no longer be able to retrieve data according to section II.2b. Please note that you will then also no longer be able to use Home Connect Plus to control Homematic IP.
At any time, you can request information about the stored data, the purpose of storage and its origin as described above. In addition, there is a right to correction, blocking and deletion of personal data in accordance with the statutory provisions. A corresponding request or a request for correction, blocking or deletion of personal data is possible via firstname.lastname@example.org.
Your eQ-3 Team