Privacy Policy for the Use of datasphere

datasphere provides a live webservice to public and private entities (“Organisations”) to raise situational awareness about the hydro-meteorological situation based on own and/or 3rd party information. This allows registered users (“Users”/“You”) to analyse the impact on their specific situation including alarming.

Next to the general KISTERS privacy policy the following topics apply for datasphere users:

User Registration

The usage of datasphere requires a personal registration and an access authorization ("Account"). Accounts may be created by the customer managers or support agents (employees of the KISTERS Group or of partner companies) (“Support”) or by designated Users within Your Organisation (“CustomerAdmin”).

For the Account registration, the following data will be recorded:

  • Name
  • Email
  • Organisation
  • Address (optional)
  • User role (permissions)
  • Language and time zone

The data is used for the management of Your access rights to the application, personalization of the application and the direct communication between You and Your Support.

This data is managed by and accessible to Your CustomerAdmin, the Support and the datasphere Administration (“PortalAdmin”). It will not be transmitted to any third party without Your explicit consent. With the request for the registration of an Account You consent to the usage of this data for the purposes described above.

Alarm Recipients & Notifications

You may configure alarms to be sent by datasphere. The list of alarm message recipients (“Recipients”) per Organisation contains contacts independently from the list of registered Users, including the following personal information:

  • Name
  • Description (optional)
  • Email (optional)
  • Phone number (optional)

Access to the data of Recipients is restricted to You, Your CustomerAdmin, the Support and the PortalAdmin. As the data processor, You and Your Organisation are responsible for the management of data protection of Recipient’s data.

Logging and Audit Trail

You can only use datasphere after successful login to Your Account with valid authorization data. Anonymous use or access is neither intended nor granted.

In datasphere all actions are logged which relate to the creation, modification or amendment of

  • User accounts
  • Locations and time series
  • Alarm configurations
  • Alarm recipients

The log contains the time and type of action and the executing Account, to ensure a revision-proof recording of all relevant actions. This information is visible to Your CustomerAdmin, the Support and the PortalAdmin. By logging in to datasphere You consent to the storage of this data.

Access Restriction

Users can only access Organisation-specific content, which are assigned to their Organisation. Support and PortalAdmin are the primary contact points for support requests and therefore have access to the Organisation-specific content of all Organisations.

Privacy

Support and PortalAdmin are committed to the confidential treatment and secrecy of the data to which they gain access in the course customer support and system maintenance. Nevertheless, it is strongly recommended to avoid storing data which are subject to special confidentiality protection.

Cookies

datasphere uses so called "Cookies". These are small pieces of data sent from datasphere which are stored on Your computer by Your web browser. These cookies contain among others information on Your authentication and User-specific settings that are selected by You while working with datasphere, e.g. the definition of visible / invisible columns in tables. This information is exclusively processed by datasphere. You may prohibit the storage of cookies by choosing a corresponding setting in Your web browser. However, we point out that with such configuration You might potentially not be able to use all functions of datasphere to their full extent.

Specifically, for datasphere, the prohibition of the use of cookies will have the effect that You will have to re-login very frequently. Therefore, it is not recommended for the sake of productive usage of the system.

Website Analytics

We want to process as little personal information as possible when you use our website. That's why we've chosen Fathom Analytics for our website analytics, which doesn't use cookies and complies with the GDPR, ePrivacy (including PECR), COPPA and CCPA. Using this privacy-friendly website analytics software, your IP address is only briefly processed, and we (running this website) have no way of identifying you. As per the CCPA, your personal information is de-identified. You can read more about this on Fathom Analytics' website.

The purpose of us using this software is to understand our website traffic in the most privacy-friendly way possible so that we can continually improve our website and business. The lawful basis as per the GDPR is "Article 6(1)(f); where our legitimate interests are to improve our website and business continually." As per the explanation, no personal data is stored over time.

SMS Notifications

If SMS notifications are enabled for a user, the application uses MessageBird (Bird) as a third-party service provider to deliver SMS messages. For this purpose, the user's mobile phone number and the content of the SMS notification are transmitted to MessageBird solely for the purpose of message delivery. MessageBird processes this information on our behalf as a communications service provider. Users who are configured to receive SMS notifications may therefore be identifiable within MessageBird's systems by their phone number. SMS notifications are only sent to recipients configured by the customer or the customer's administrators. Further information about MessageBird's privacy practices can be found at: https://www.bird.com/legal/privacy

Mobile

The datasphere framework provides a mobile application which can be installed via Apple AppStore and Google Playstore. When starting the app You can provide user consent to the following sections:

  • Essential:
    All information necessary to grant the basic features of this application. This includes chaching of recent selection or filter criteria
  • Comfort:
    in this mode the app will locally store Your datasphere user credentials using its highly secure built-in encryption system of your mobile phone. This enables auto-login when you return the next day.
  • Diagnostics:
    Sometimes things go wrong. We are keen to know about the problems which occur in our software. The diagnostics option automatically reports this problems to a cloud platform called sentry.io. This reports include details about the problem and the general device type, but they do not include any specific user- or device-IDs.

Firebase Cloud Messaging (FCM)

  • The datasphere mobile application uses Firebase Cloud Messaging (FCM), a push notification service provided by Google. FCM enables us to deliver notifications and alerts to your mobile device.
  • For this purpose, a unique device token and technical information required for message delivery may be transmitted to Google. Depending on your device and operating system, additional data such as IP addresses or device identifiers may be processed by Google in connection with the delivery of notifications.
  • Push notifications are only sent if enabled by the user in the application or device settings. Further information about Google's data processing practices can be found in Google's Privacy Policy: https://policies.google.com/privacy
  • The legal basis for processing is our legitimate interest in providing timely service notifications and alerts (Art. 6(1)(f) GDPR) or, where applicable, the user's consent (Art. 6(1)(a) GDPR).

Concluding Remarks

You must be aware that there are inherent security risks in transmitting data via the internet, because it is impossible to safeguard completely against unauthorized access by third parties.

We oppose the use of any available contact information on this website by a third party for sending unsolicited advertisements. As the website provider, we reserve the express right to take legal action against unsolicited mailing or e-mailing of spam and other similar advertising materials.

Back to the top