Privacy Policy
Our Privacy Policy will take effect on July 10, 2023. From this date onwards, this Privacy Policy can provide privacy details on how we manage your personal information for E-Smart products and services. Please take a moment to familiarize yourself with our Privacy Policy and let us know if you have any questions.
Our commitment to you
E-Smart Group Oy (hereinafter referred to as “E-Smart”, “we”, “our” or “us”) highly value your privacy. E-Smart products are smart devices for controlling heaters, coolers, humidifiers and dehumidifiers. Your privacy is extremely important to us. This Privacy Policy is a statement and commitment covering privacy of E-Smart hardware device, E-Smart mobile app and E-Smart cloud-based services. We recommend that you carefully read the E-Smart Privacy Policy and pay particular attention to provisions on “protection, security measures, and cross-border data transfers”. This Privacy Policy was formulated to fully take your needs into account. It is important that you fully understand our personal information collection and usage practices and ensure that you are ultimately able to exercise control over the personal information you provide to us. This Privacy Policy sets out how we collect, use, disclose, process, and store any information that you provide to us when you use E-Smart products. As used in this Privacy Policy, “personal information” means information that can be used to identify an individual, either from that information alone or in conjunction with other related information. We will only use this information in strict accordance with this Privacy Policy. Ultimately, we hope to give our users the best experience possible. Should you have any questions about our data handling practices as described in this Privacy Policy, please contact us by email using [email protected] so that we can respond to your specific concerns.
I. What Information We Collect and How We Use It
(I) Circumstances which require you to authorize us to collect and use your personal information
Personal information is collected in order to provide you with products and/or services as well as to ensure legal compliance on our part with applicable laws, regulations, and other regulatory documents. You have the right to choose whether or not to provide this information. However, in most cases, if you do not provide such information, we may be unable to provide corresponding services to you, or we may be unable to respond to a problem you encounter. These features include:
(1) Smart device connections
In order to provide you with E-Smart services and allow you to securely connect to and manage smart devices, we may collect your Wi-Fi information, location information, information related to your mobile phone and smart device. This information will be used to provide you with various functionality including pairing with and connecting to smart devices, discovering nearby devices, and device management. Specific examples involving the above information are set out below:
Mobile phone related information: Hardware-based identifiers (MAC address, Android ID), phone model, OS version, OS language, country or region, App Store version, screen size and resolution, CPU, and display device related information.
Information to be collected during connection to a smart device: Based on the type of the smart device you need to get connected to, we may collect the following information: Wi-Fi information (SSID, BSSID, MAC address of Wi-Fi, Wi-Fi password), MAC address of the device, and device ID. Please note, that the Wi-Fi password is required for establishing the internet connection from E-Smart device and E-Smart cloud-services. This password is stored on the mobile phone and in the E-Smart device, but never transmitted to the E-Smart cloud-service or anywhere else outside of your home network.
(2) Using smart devices for climate control
We may collect information that you provide relating to room settings for smart devices in order to facilitate smart home management. This will allow us to continuously improve smart climate control algorithms and provide your with greater convenience and user experience.
(3) App and smart device updates:
To ensure you can continue enjoying the latest E-Smart services, we may use the version information of your E-Smart device, E-Smart app and phone model in order to provide you with software updates. We may also collect a list of your connected smart devices and associated version information in order to provide you with smart device updates so that you can use the latest version of the service (including firmware version).
(4) Weather forecasts (smart device connections):
One of the key features of E-Smart product is to provide highly optimised climate control using weather forecasts and artificial intelligence algorithms. In order to enjoy this feature, we collect your location information to get location specific weather forecasts as well as sunrise and sunset settings. Please note, that the location information is transmitted with a high degree of inaccuracy – deliberately to ensure maximum privacy without compromising functionality.
(II) Non-personal information
We may also collect other types of information which are not directly or indirectly linked to an individual and which may not be defined as personal information according to applicable local laws. Such information may include statistical data generated when you use a specific service, such as including clicks, page redirects, and browsing time Such information is collected in order to improve the services we provide to you.
II. Sharing Your Personal Information with Third Party Service Providers
To help us provide you with products and services described in this Privacy Policy, we may, where necessary, share your personal information with our third party service providers and business partners. We will conduct due diligence and have contracts in place to ensure that third-party service providers comply with the applicable privacy laws in your jurisdiction. For hosting and processing purposes, we utilise the platform services of Amazon AWS. Following elements of personal data are transmitted to and stored within Amazon AWS: Location Information, Mobile Phone-related information, Device-related information including MAC address and Room-related information such as temperature and humidity. Please note that we never transmit or store Names, Email addresses, Wi-Fi information and IP addresses outside of your home network. When we share your personal information with these third parties, we use encryption technology or other means to keep your information secure. Furthermore, we expect third parties to take adequate measures to safeguard your information and to strictly comply with applicable laws, regulations, and regulatory requirements.
III. Retention Policy
We will retain personal information for the period of time needed to fulfill the purpose for which it was collected as described in this Privacy Policy, or we will retain personal information in order to comply with applicable legal requirements. We will cease to retain your personal information and will delete or anonymize it once the purpose of collection is fulfilled, or after we confirm your request for deletion or cancellation, or after we discontinue the corresponding product or service. We will continue to retain relevant information in accordance with applicable laws even if further information processing is unrelated to the original purpose of collection, provided that doing so would be in the public interest or for scientific or historical research or statistical purposes.
IV. Your Rights
(I) Your rights to your personal information
Subject to the applicable laws and regulations of your country or region, you have the right to request access to, correct, and/or delete any personal information we have about you (hereinafter referred to as a “request”). For more information, please write us a letter or contact us by using [email protected] . Most laws require a data subject to meet certain requirements when making a request. This Privacy Policy requires any request you make to meet the following conditions:
To safeguard your personal information, your request should be made in writing through our designated request channel.
Provide enough information for us to verify your identity and ensure that the requester is the data subject or is otherwise legally authorized to request the information;
Once we have a sufficient amount of information and confirm that we are able to process your request, we will respond to your request within the period specified by applicable data protection laws. Specifically:
We may provide to you, in accordance with your request and applicable laws and regulations, a free copy of the record of personal information about you that we have collected and processed. However, if you make an additional request regarding related information, we reserve the right, pursuant to applicable law, to charge you a reasonable fee for your data access request based on actual management costs involved.
If you believe that any information we have about you is incorrect or incomplete, you may request to correct or modify your personal information based on the purpose of use.
Subject to your applicable laws and regulations, you may have the right to ask us to delete your personal data. We will conduct an evaluation according to your request for deletion and, if corresponding rules are met, we will take corresponding steps, including technical measures, to carry out your request. After you delete or after we assist you in deleting your information, it may not be possible for us to immediately delete corresponding information from our backup systems due to applicable laws and security technologies. In such event, we will ensure your personal information is kept secure and prevent it from being subjected to any further processing until the backup can be cleared or anonymized.
We have the right to refuse to process requests considered to be frivolous or vexatious, requests that harm the privacy of others, extremely unrealistic requests, requests that would require a disproportionate technical effort, requests that are not required to be granted under local law, and requests involving information already available to the public or given under confidential conditions. We may also refuse a request in cases where we believe that certain aspects of a request to delete or access data might cause us to be unable to legally use the data for the aforementioned anti-fraud and security purposes.
(II) Withdrawal of consent
You may withdraw your consent for the collection, use, and/or disclosure of your personal information in our possession or control by submitting a request. You may contact us for relevant requests by using [email protected] . We will process your request within a reasonable time frame from the time when the request was received, and thereafter not collect, use and/or disclose your personal information as per your request. Please note that your withdrawal of consent could result in certain legal consequences. Depending on the extent to which you authorize us to process your personal information, it may mean that you will no longer be able to enjoy the use of E-Smart products or services. However, any decision on your part to withdraw your consent or authorization will not affect personal information processing previously performed with your permission.
V. How your personal information is transferred globally
Currently, E-Smart uses Amazon AWS data centers in Europoe. For the purposes of this Privacy Policy, your information may be transferred to these data centers according to applicable laws.
Since we share your personal information with our Third Party Service Providers and business partners, your information may also be transferred to other countries or regions. The jurisdiction of these facilities worldwide may not implement the same personal information protection standards as in your jurisdiction. Risk may exist depending on different data protection laws. However, we carefully choose our Third Party Servicer Providers and business partners and expect them to to take adequate measures to safeguard your information and to strictly comply with applicable laws, regulations, and regulatory requirements.
VI. Contact Us
If you have any questions or feedback regarding this Privacy Policy, or if you have any questions regarding how we collect, use, or disclose your personal information, please contact us by using [email protected] and mention that your message is in reference to the “Privacy Policy”. If you have a particularly critical issue that needs to be addressed, we may ask you to provide us with more information.