Privacy Policy
Last updated: 15 August 2026
This policy explains what personal data we process when you visit lyvra.energy, use the Lyvra app, or connect a smart meter dongle, charger or solar inverter to your account. It applies to all Lyvra services and is written to meet Articles 13 and 14 of the GDPR.
1. Who is responsible for your data
The data controller for the processing described here is:
For any privacy question or to exercise your rights, contact us at the privacy address above. We answer within one month, as required by the GDPR.
2. What we process, why, and for how long
We only process data we need to run the service you asked for. The table below is the complete picture.
| Category | Examples | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Account data | Name, email address, password (hashed), language, time zone | Creating and securing your account, signing you in, support | Performance of a contract (Art. 6(1)(b)) | Life of the account, then deleted after the 30-day grace period |
| Location data | Address, postcode, country and coordinates of the home or site you add | Matching your site to the right weather, solar forecast and grid tariffs | Performance of a contract (Art. 6(1)(b)) | Life of the account |
| Smart meter data | Electricity and gas readings from your P1 port, import and export, meter identifiers | Showing your usage, calculating costs, driving smart charging decisions | Performance of a contract (Art. 6(1)(b)) | Life of the account; see "Smart meter data" below |
| Charging data | Charging sessions, energy delivered, start and stop times, schedules, charge point identifiers, RFID tags | Running and reporting on charging, smart and solar charging, load balancing | Performance of a contract (Art. 6(1)(b)) | Life of the account |
| Solar and battery data | Production readings, forecasts, inverter and battery identifiers | Showing production and matching consumption to your own generation | Performance of a contract (Art. 6(1)(b)) | Life of the account |
| Connected account credentials | Tokens for services you link yourself, such as an Easee or Peblar account | Reading from and controlling the devices you have linked | Performance of a contract (Art. 6(1)(b)) | Until you unlink the service or delete your account |
| Payment data | Subscription status, transaction and invoice records, the last four digits and card brand | Taking payment for Lyvra+ and hardware, invoicing, refunds | Contract (Art. 6(1)(b)) and legal obligation for invoices (Art. 6(1)(c)) | Invoices kept 7 years under Dutch tax law; other payment data for the life of the account |
| Device and push data | Device model, operating system, app version, push notification token | Sending the alerts you switch on and keeping the app working on your device | Performance of a contract (Art. 6(1)(b)) | Until you turn notifications off, sign out, or delete your account |
| Diagnostics and crash reports | Crash traces, error messages, an anonymous app identifier | Finding and fixing faults in the app and backend | Consent in the app (Art. 6(1)(a)) | 90 days |
| Usage analytics | Screens opened, features used, session length, device type | Understanding which features are worth improving | Consent in the app (Art. 6(1)(a)) | 14 months |
| Website data | IP address, browser type, pages visited, referring page | Serving and securing the website, measuring traffic | Legitimate interest in a working, secure site (Art. 6(1)(f)); consent for non-essential cookies | Server logs up to 12 months |
| Contact and support | Your name, email address and the content of your message | Answering your question and keeping a record of the exchange | Legitimate interest in answering you (Art. 6(1)(f)) | 24 months after the conversation closes |
| Newsletter | Email address, language, subscription date | Sending product updates you asked for | Consent (Art. 6(1)(a)) | Until you unsubscribe |
3. Smart meter data, in plain terms
Detailed energy readings say a lot about a household โ when you are home, when you cook, when you sleep. We treat them accordingly:
- Readings come from the P1 port of your own meter, via a dongle you install yourself. Nothing is read from your energy supplier or grid operator unless you explicitly connect that account.
- We store readings at the coarsest granularity that still makes the feature work, and aggregate older detailed readings into hourly and daily totals.
- Readings are linked to your account and the site you added them to, never to a named individual beyond that.
- We never sell energy data, and we do not share it with energy suppliers, advertisers or data brokers.
- You can disconnect a dongle at any time, which stops collection immediately.
If we ever want to use meter data for something outside the service you signed up for, we will ask you first.
4. Automated decisions
Lyvra makes automated decisions about when your devices run โ for example, starting a charging session when prices are low or your solar production is high. These decisions affect your devices, not your legal rights or your access to any service, and you can override any schedule or switch smart charging off at any time. We do not carry out profiling in the sense of Article 22 of the GDPR, and we do not use your data to make decisions about credit, insurance, employment or pricing.
5. Who else processes your data
We do not sell personal data. We use the processors below to run the service, each under a data processing agreement that limits them to our instructions.
| Processor | What they do | Where |
|---|---|---|
| Hosting provider | Runs our servers and databases | EU |
| Google (Firebase) | Push notifications, crash reporting, app analytics | EU and US, under the EU-US Data Privacy Framework |
| Sentry | Backend and app error monitoring | EU and US, under Standard Contractual Clauses |
| Mollie | Payment processing for subscriptions and hardware | EU (Netherlands) |
| Stripe | Payment processing for subscriptions | EU and US, under Standard Contractual Clauses |
| Apple, Google | In-app purchase and subscription validation | EU and US |
| Cloudflare | Bot protection on our forms | EU and US, under Standard Contractual Clauses |
| Email provider | Sending transactional and support email | EU |
Services you link yourself โ an Easee or Peblar account, for example โ are run by those companies under their own privacy policies. We only exchange what is needed to read and control your devices. We may also disclose data where the law requires it, or to establish or defend a legal claim.
6. Transfers outside the EU
Your account and energy data are stored on servers in the EU. Some of the processors above are US companies. Where data reaches them, the transfer relies on the European Commission's adequacy decision for the EU-US Data Privacy Framework, or on Standard Contractual Clauses together with additional technical measures. You can ask us for a copy of the safeguards used.
7. Your rights
Under the GDPR you can:
- Access the personal data we hold about you, and get a copy of it
- Correct data that is wrong or incomplete
- Delete your account and data โ from Settings in the app, or via our deletion page
- Export your data in a portable, machine-readable format
- Restrict or object to processing based on legitimate interest
- Withdraw consent at any time, for analytics, diagnostics or the newsletter, without affecting processing already carried out
Exercise any of these from Settings in the app or by emailing our privacy address. If you think we have handled your data wrongly, you can also complain to the Dutch Data Protection Authority.
8. How we protect your data
We encrypt traffic in transit (HTTPS for the app and website, TLS for the dongle's MQTT connection), hash passwords, restrict database access to the systems that need it, and keep audit records of administrative actions on accounts. No system is perfect: if a breach puts your rights at serious risk, we will tell you and the supervisory authority as the GDPR requires.
9. Cookies
The website uses essential cookies to work, and analytics or marketing cookies only if you allow them. You can change your choice at any time through the cookie settings link in our footer. Our cookie policy sets out each cookie in detail.
10. Children
Lyvra is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
11. Changes to this policy
We update this policy when the service changes. The date at the top always reflects the current version. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect.