MENTIONS LÉGALES

Politique de confidentialité.

Comment nous collectons, utilisons et protégeons les données personnelles sur ce site web. Dernière mise à jour le 15 mai 2026.

1. Who is responsible — controller & data protection officer

Controller (within the meaning of Art. 4(7) GDPR / Art. 4 Nr. 7 DSGVO):

Off-Grid Europe GmbH

Vorhof 1, 88633 Heiligenberg, Germany

Email: info@off-grid-europe.com

Phone: +49 (0) 7552 937 99 08

Represented by the General Manager: Christiane Kragh

Commercial Registry: Freiburg HRB 711067 — VAT ID: DE295532453

Data Protection Officer (Art. 37 GDPR / § 38 BDSG):

We have appointed an external Data Protection Officer:

DataGuard GmbH, Kaufingerstraße 15, 80331 München, Germany

Email: info@dataguard.de — Website: https://www.dataguard.de

For any matters concerning the processing of your personal data, including the exercise of your rights, you may contact us or our DPO directly using the details above.

2. Scope of this notice and your rights at a glance

This notice explains what personal data we process when you visit offgrideurope.com (including its subdomains such as dev.offgrideurope.com and configurator.offgrideurope.com), the purposes and legal bases of that processing, the recipients of your data, how long we retain it, and the rights you have under Articles 12–22 GDPR.

Your rights at a glance. You have the right to access, rectification, erasure, restriction, data portability, and objection. Where processing is based on consent, you may withdraw that consent at any time with effect for the future. You also have the right to lodge a complaint with a supervisory authority (see section 13).

Plain language obligation. We have written this notice in clear and plain language in accordance with Art. 12(1) GDPR. If anything is unclear, please contact us — we will be glad to explain.

Voluntary nature. Providing your personal data is voluntary. There is no statutory or contractual obligation to provide it. If you do not provide it, however, we may be unable to respond to your enquiry or process a quote request.

3. Visiting our website — server log data

Each time you access our website, our hosting infrastructure (see section 4) automatically collects information that your browser transmits to us. This data is technically necessary to display the website to you and to ensure its stability and security.

Data processed: IP address (anonymised or shortened where feasible), date and time of the request, the URL requested, the referring URL, the HTTP status code, the amount of data transferred, the browser and operating system you use, and your approximate region derived from the IP address.

Purpose: delivering the website, troubleshooting, IT security (defence against DDoS, abuse, and bot traffic).

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in operating a stable, secure website.

Retention: server log data is automatically deleted or anonymised after at most 14 days, unless an IT-security incident requires us to keep it longer to investigate or substantiate a claim.

This log data is not combined with other data sources and is not used to identify individual visitors outside of security incidents.

4. Hosting, content delivery, and IT infrastructure

Our website is operated on the following infrastructure. All providers are bound to us by data-processing agreements (DPAs) under Art. 28 GDPR.

Cloudflare — Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA (and Cloudflare Germany GmbH, Rosental 7, c/o Mindspace, 80331 München). We use Cloudflare Workers, Cloudflare Pages, Cloudflare R2 (S3-compatible object storage), and the Cloudflare CDN to deliver the site and protect it against abuse. Cloudflare processes IP addresses, request metadata, and connection information on our behalf.

Hetzner Online GmbH — Industriestr. 25, 91710 Gunzenhausen, Germany. Hetzner hosts our Directus content management system in Germany (servers in the EU). Editorial content is delivered from there.

Odoo S.A. (Odoo.sh) — Rue Laid Burniat 5, 1348 Louvain-la-Neuve, Belgium. Odoo.sh hosts our CRM. Quote requests and contact enquiries from this website are recorded there as leads (see section 6).

Third-country transfers. Cloudflare is a US-based provider. Where personal data is transferred to the United States, the transfer is safeguarded by Cloudflare's certification under the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795) and by Standard Contractual Clauses (SCCs) under Commission Decision (EU) 2021/914. Hetzner and Odoo.sh process data within the EU/EEA.

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in providing a fast, reliable, secure website served from EU edge locations.

5. Contact form

If you use our contact form, we process the data you submit in order to handle your enquiry and respond to you.

Data we collect: name, email address, company (optional), subject (optional), the content of your message, the Cloudflare Turnstile verification token, and — server-side, for security and abuse-prevention only — your IP address and browser user-agent, plus a timestamp.

Required vs. optional. Fields marked as required (name, email, message, GDPR consent) must be filled in. Other fields are optional.

GDPR consent. A confirmation checkbox ("I have read the privacy policy and agree…") must be ticked before the form can be submitted. The checkbox is not pre-ticked — your consent is freely given, specific, informed, and unambiguous in accordance with Art. 4(11) and Art. 7 GDPR.

Purpose & legal basis:

  • handling your enquiry: Art. 6(1)(b) GDPR (pre-contractual measures) if your enquiry relates to a contract or potential contract;
  • otherwise Art. 6(1)(f) GDPR (our legitimate interest in answering enquiries effectively);
  • and Art. 6(1)(a) GDPR (your consent), which you may withdraw at any time with effect for the future.

Recipients. Your enquiry is sent by email through Amazon Web Services (AWS) Simple Email Service (Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg, with sub-processing by Amazon.com Inc. in the USA under the EU-US DPF and SCCs). The email is received in our company mailbox.

Retention. We delete the data once your enquiry has been finally handled, unless statutory retention obligations (e.g. § 257 HGB, § 147 AO — up to 10 years for commercial/tax-relevant correspondence) require longer storage, or unless the enquiry leads to a contract.

6. Quote requests via the product configurator

Our product configurator (e.g. for the Ohmsbox BESS) lets you build a configuration and submit it as a quote request.

Data we collect: name, email address, company name, company website, your message (optional), the configuration you assembled (product, options, quantities, totals such as kWh storage and kVA), the GDPR consent flag, plus a honeypot field used solely for bot detection. Server-side we additionally log your IP address, user-agent, and a Cloudflare request ID for rate-limiting and abuse prevention.

GDPR consent. The same not-pre-ticked confirmation checkbox applies. Submission is rejected if consent is not granted.

Purpose & legal basis: preparing and responding to your quote request is a pre-contractual measure under Art. 6(1)(b) GDPR. To the extent we rely on your consent for the storage and follow-up communication beyond the immediate quote, the basis is Art. 6(1)(a) GDPR.

Recipients. Quote requests are written to our Odoo CRM (crm.lead) hosted on Odoo.sh in Belgium. The full configuration is included in the lead description so our sales team can prepare an offer. Tagged with "Web Configurator" for internal routing.

Retention. Leads that do not lead to a contract are deleted or anonymised at the latest 6 months after the last meaningful contact. Leads that lead to a contract are kept for the duration of the customer relationship plus the statutory retention periods (§ 257 HGB, § 147 AO).

7. Cookies, local storage, and tracking

This website uses only technically necessary cookies and storage within the meaning of § 25(2) Nr. 2 TTDSG. We do not use marketing cookies, analytics cookies, social-media pixels, or cross-site tracking, and we do not display a cookie banner because none of the storage we use requires consent under the TTDSG.

What we store on your device:

  • Cloudflare Turnstile session cookies/tokens — set when you interact with our contact form, used to confirm you are a human and not a bot. See section 8.
  • Local form draft state — temporary in-memory state held only while you have the configurator tab open. It is not persisted to localStorage or cookies.
  • No advertising or analytics cookies.

Legal basis: § 25(2) Nr. 2 TTDSG — storage strictly necessary to provide a service expressly requested by you. No consent is required for these items.

You can configure your browser to block or delete cookies at any time. Doing so may impair the contact form's spam protection.

8. Cloudflare Turnstile (spam protection)

To protect our contact form from spam and automated abuse, we use Cloudflare Turnstile, a CAPTCHA-replacement service provided by Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA).

Data processed: Turnstile analyses signals such as the IP address, browser and device characteristics, interaction patterns, and the validity of an issued challenge token to assess whether the form submission is from a human.

Purpose: preventing bot submissions, brute-forcing, and form spam.

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in protecting our infrastructure and our mailbox from abuse.

Third-country transfer: Cloudflare may process this data in the United States. The transfer is safeguarded by Cloudflare's participation in the EU-US Data Privacy Framework and by Standard Contractual Clauses (SCCs). Cloudflare's privacy notice is available at https://www.cloudflare.com/privacypolicy/.

9. Embedded media — YouTube in privacy-enhanced mode

Where we embed video content from YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent: Google LLC, USA), we use the privacy-enhanced mode (youtube-nocookie.com). In this mode YouTube does not set cookies or share tracking information with Google until you actively click to play a video. Where possible, we additionally use a click-to-load pattern, so that the YouTube player is only loaded once you press "play".

Once you press play, YouTube may process technical data (including your IP address) to deliver the video and may set cookies on your device. The legal basis for this processing is your consent (Art. 6(1)(a) GDPR), expressed by your active click to play.

For more information see Google's Privacy Policy at https://policies.google.com/privacy.

10. Recipients & categories of recipients

Personal data is disclosed only to the following categories of recipients, and only to the extent strictly necessary:

  • our employees in sales, customer service, and IT, on a need-to-know basis;
  • our processors under Art. 28 GDPR — Cloudflare (US, hosting & spam protection), Hetzner (DE, hosting), Odoo S.A. (BE, CRM), Amazon Web Services EMEA SARL (LU, transactional email), and DataGuard GmbH (DE, data-protection officer services);
  • tax advisers, auditors, and legal counsel, where required and bound by professional secrecy;
  • public authorities and courts, where we are obliged by law to disclose (e.g. tax authorities, criminal-investigation authorities upon a lawful order).

We do not sell personal data, and we do not transfer it for the recipients' own marketing purposes.

11. Retention periods

We retain personal data only for as long as necessary for the purpose for which it was collected, or as long as required by statutory retention obligations.

Data Retention
Server log data up to 14 days
Contact-form enquiries (no contract) until the matter is closed, then deleted
Quote requests / leads (no contract) up to 6 months after last meaningful contact
Customer records (after a contract) duration of relationship + statutory retention (§ 257 HGB, § 147 AO — up to 10 years for commercial/tax-relevant documents)
Cloudflare security logs per Cloudflare's data-retention policy

After the relevant period expires, data is deleted or anonymised in accordance with our internal deletion concept.

12. Your rights under the GDPR

You have the following rights regarding your personal data, free of charge and exercisable at any time by contacting us or our Data Protection Officer (see section 1):

  • Right of access (Art. 15 GDPR) — to obtain confirmation as to whether we process your data and, if so, a copy of that data and the information listed in Art. 15.
  • Right to rectification (Art. 16 GDPR) — to have inaccurate data corrected or incomplete data completed.
  • Right to erasure / "right to be forgotten" (Art. 17 GDPR) — to have your data deleted where the conditions of Art. 17 are met.
  • Right to restriction of processing (Art. 18 GDPR).
  • Right to data portability (Art. 20 GDPR) — to receive the data you have provided to us in a structured, commonly used, machine-readable format and to have it transmitted to another controller.
  • Right to object (Art. 21 GDPR) — where processing is based on Art. 6(1)(e) or (f), you may object at any time on grounds relating to your particular situation. Where data is processed for direct marketing, you may object at any time without giving reasons.
  • Right to withdraw consent (Art. 7(3) GDPR) — where processing is based on your consent, you may withdraw it at any time with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal.
  • Right not to be subject to automated decisions (Art. 22 GDPR) — we do not use automated decision-making or profiling that produces legal effects concerning you.

To exercise any of these rights, email info@off-grid-europe.com or our DPO at info@dataguard.de. We will respond within one month in accordance with Art. 12(3) GDPR.

13. Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right under Art. 77 GDPR to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.

The authority competent for Off-Grid Europe GmbH is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW)

Lautenschlagerstraße 20, 70173 Stuttgart, Germany

Phone: +49 (0) 711 615541-0

Email: poststelle@lfdi.bwl.de

Website: https://www.baden-wuerttemberg.datenschutz.de

A list of all German supervisory authorities is available at https://www.bfdi.bund.de.

14. SSL/TLS encryption, data security & changes to this notice

SSL/TLS encryption. This site uses SSL/TLS encryption for all connections, recognisable by the https:// prefix and the lock symbol in your browser's address bar. Data transmitted via this site is therefore protected against interception by third parties.

Data security. We maintain appropriate technical and organisational measures (TOMs) under Art. 32 GDPR — including access controls, encryption at rest and in transit, role-based authorisation, regular backups, and vulnerability management — to protect personal data against accidental or unlawful destruction, loss, alteration, and unauthorised disclosure or access.

No automated decision-making. We do not use automated decision-making within the meaning of Art. 22 GDPR.

Changes to this notice. We may update this privacy notice from time to time to reflect changes in our processing activities or applicable law. The current version is always published on this page; the date at the top of this notice indicates the latest revision. For material changes, we will inform users in an appropriate manner.