Privacy Policy
1. Data Protection at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit this website or use our apps and services (PDF Content Search for iOS and macOS, PDF.Scanner. for Android, Inkra for macOS and iPadOS, and SolarPulse for web, iPhone and iPad). Personal data is any data that can personally identify you. For detailed information on data protection, please refer to our complete privacy policy listed below this text.
Data Collection on This Website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find the contact details in the section “Information about the Responsible Party” in this privacy policy.
How do we collect your data?
Your data is collected when you provide it to us. This could, for example, be data you send us via email or telephone. Other data is automatically collected by our IT systems when you visit the website. This is primarily technical data (e.g., internet browser, operating system, or time of page access). This data is collected automatically as soon as you enter this website.
What do we use your data for?
Some of the data is collected to ensure the proper functioning of the website. Other data may be used to analyze your user behavior.
What rights do you have regarding your data?
You always have the right to receive information about the origin, recipient, and purpose of your stored personal data free of charge. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. You also have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
2. Hosting
We host the content of our website with the following provider:
External Hosting
This website is hosted externally. The personal data collected on this website is stored on the servers of the host(s). This may include IP addresses, contact requests, meta and communication data, contract data, contact details, names, website accesses, and other data generated via a website.
External hosting is carried out for the purpose of fulfilling contracts with our potential and existing customers (Art. 6 para. 1 lit. b GDPR) and in the interest of secure, fast, and efficient provision of our online offering by a professional provider (Art. 6 para. 1 lit. f GDPR).
3. General Information and Mandatory Information
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.
When you use this website, various personal data is collected. Personal data is data with which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this happens.
We would like to point out that data transmission over the Internet (e.g., when communicating by email) can have security gaps. Complete protection of data against access by third parties is not possible.
Information about the Responsible Party
The responsible party for data processing on this website is:
Jürgen Koller Software GmbH
Wilhelmstr. 5
74072 Heilbronn
Germany
Phone: +49 7131 9244166
Email: datenschutz@juergenkoller.software
The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (e.g., names, email addresses, etc.).
Storage Duration
Unless a more specific storage period has been specified within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or revoke consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial retention periods); in the latter case, deletion will take place after these reasons cease to apply.
Retention Periods and Backup Storage
Certain personal data is subject to statutory retention obligations that prevent immediate complete deletion. In particular, the following retention periods apply under German law:
- 10 years: Tax and accounting-relevant data such as invoices, accounting records, and annual financial statements (§ 147 AO, § 257 HGB)
- 6 years: Commercial correspondence such as order confirmations and business letters (§ 257 HGB)
If you request deletion of your data (e.g., by deleting your customer account), your data will be removed immediately from all active systems. Data subject to statutory retention obligations will be stored in secured, immutable backups (WORM storage). This data is locked and no longer accessible for operational purposes. After the respective statutory retention period expires, final deletion will occur automatically.
All other personal data not subject to statutory retention obligations will be deleted immediately and completely upon a deletion request.
Legal basis: Art. 6 para. 1 lit. c GDPR (compliance with a legal obligation) in conjunction with § 147 AO, § 257 HGB.
Revocation of Your Consent to Data Processing
Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to Object to Data Collection in Special Cases and to Direct Advertising (Art. 21 GDPR)
IF DATA PROCESSING IS BASED ON ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING SERVES TO ASSERT, EXERCISE, OR DEFEND LEGAL CLAIMS (OBJECTION UNDER ART. 21 PARA. 1 GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT ADVERTISING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH ADVERTISING; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS RELATED TO SUCH DIRECT ADVERTISING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT ADVERTISING PURPOSES (OBJECTION UNDER ART. 21 PARA. 2 GDPR).
Right to Lodge a Complaint with the Competent Supervisory Authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, particularly in the member state of their habitual residence, place of work, or place of the alleged violation. The right to lodge a complaint exists without prejudice to other administrative or judicial remedies.
Right to Data Portability
You have the right to have data that we process automatically based on your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another responsible party, this will only be done to the extent that it is technically feasible.
Information, Deletion, and Correction
Within the framework of the applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipient, and the purpose of data processing and, if applicable, a right to correction or deletion of this data. For this purpose, as well as for further questions on the subject of personal data, you can contact us at any time.
Right to Restriction of Processing
You have the right to request the restriction of the processing of your personal data. For this, you can contact us at any time. The right to restriction of processing exists in the following cases:
- If you dispute the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the verification, you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data happened/is happening unlawfully, you can request the restriction of data processing instead of deletion.
- If we no longer need your personal data, but you need it to exercise, defend, or assert legal claims, you have the right to request restriction of the processing of your personal data instead of deletion.
- If you have lodged an objection pursuant to Art. 21 para. 1 GDPR, a balancing of your and our interests must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
4. Data Collection on This Website
Cookies
Our website uses so-called “cookies”. Cookies are small data packets and do not cause any damage to your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are automatically deleted after your visit. Permanent cookies remain stored on your device until you delete them yourself or until they are automatically deleted by your web browser.
Cookies can be from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within websites (e.g., cookies for processing payment services).
Cookies have various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g., the shopping cart function or the display of videos). Other cookies can be used to analyze user behavior or for advertising purposes.
Cookies that are necessary to carry out the electronic communication process, to provide certain functions you have requested (e.g., for the shopping cart function), or to optimize the website (e.g., cookies for measuring web audience) (necessary cookies) are stored on the basis of Art. 6 para. 1 lit. f GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies for the technically error-free and optimized provision of its services. If consent to the storage of cookies and comparable recognition technologies has been requested, processing is carried out exclusively on the basis of this consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG); consent can be revoked at any time.
You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be limited.
You can find out which cookies and services are used on this website from this privacy policy.
For the cookies and browser storage used by the AI product assistant, see the section AI Product Assistant.
AI Product Assistant
At store.juergenkoller.software, and on the home page and contact page of juergenkoller.software, you can ask a chat assistant questions about our apps, pricing and the user manuals. The assistant is labelled as an AI system; you are not talking to a person. It only becomes active when you open the chat window.
Data transmitted: your messages, the history of the current conversation and the page on which you opened the assistant. To generate the answer, this information is transmitted to OpenAI, Inc. (San Francisco, USA), together with the manual and product information the assistant draws on to answer.
Not collected: name, e-mail address, telephone number or any other contact details. The assistant does not ask for them. There is no link to your customer account.
Purpose and legal basis: answering questions about our products and how to use them. Processing is based on our legitimate interest in providing prospective and existing customers with information about our products (Art. 6 para. 1 lit. f GDPR). Using the assistant is voluntary.
Retention: on our server the conversation is held in memory for the duration of the session only and is not stored permanently. When you open the chat window we set a cookie with a random identifier to assign the session; it expires after 7 days and is required for the conversation you requested to work (§ 25 para. 2 no. 2 TDDDG). According to OpenAI, data transmitted via its application programming interface is retained for up to 30 days to detect abuse, unless longer retention is required by law, and is not used to train its models.
Storage in your browser: with your consent the assistant stores the conversation as well as the position and size of the chat window in your browser’s local storage, so that the conversation is still there on a later visit (Art. 6 para. 1 lit. a GDPR, § 25 para. 1 TDDDG). You can give or withdraw this consent at any time in the cookie settings (service “AI assistant”). Without consent the assistant works without restriction; the conversation is then lost when you leave the page.
Usage statistics: we count how often the assistant is used and whether it was able to answer questions from the manuals. These statistics contain no conversation content, no identifiers and no IP addresses, and do not allow conclusions about individual persons.
Please note: do not enter sensitive personal data in the chat. What you write is transmitted to OpenAI to generate the answer. For transfers to the USA, see the section Data Transfer to Third Countries.
5. Analysis Tools and Advertising
Matomo (formerly PIWIK)
This website uses the open-source web analysis service Matomo. With Matomo, statistics and evaluations about the use of this website can be created. For this purpose, so-called “cookies” are used, which are stored on your computer and enable analysis of your use of the website.
The information generated by the cookie about your use of this website is stored only on our server. The IP address is anonymized immediately after processing and before storage.
The use of Matomo is carried out on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the anonymous analysis of user behavior in order to optimize both its website and its advertising. If a corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, insofar as the consent includes the storage of cookies or access to information in the user’s end device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time.
IP Anonymization
For analysis with Matomo, IP anonymization is activated on this website. Your IP address is shortened by Matomo before analysis, so that it is no longer directly assignable to you.
Hosting
We host Matomo ourselves on our own servers, so that all analysis data remains with us and is not passed on.
Opt-Out
You can object to the collection and analysis of your data by Matomo. In this case, an opt-out cookie will be set in your browser, which tells Matomo that no data should be stored.
Matomo Opt-Out:
More information about Matomo and privacy can be found at: https://matomo.org/privacy/
6. Data Processing in Our Apps
The following sections describe the data processing in our apps and services PDF Content Search (iOS and macOS), PDF.Scanner. (Android), Inkra (macOS and iPadOS), and SolarPulse (web, iPhone and iPad). Personal data is only processed for the purposes described below. Sections prefixed with “Inkra” apply exclusively to the Inkra app, and the section “PDF.Scanner. for Android” applies exclusively to the Android app; sections prefixed with “SolarPulse” apply exclusively to SolarPulse; the other sections in this chapter describe PDF Content Search.
Local Data Processing
The majority of data processing takes place exclusively on your device. This includes in particular:
- Scanning and storing documents
- OCR text recognition using the Apple Vision Framework
- Local full-text search across your documents
- Storage in the local SQLite database
This locally processed data does not leave your device unless you use the features described below.
AI-Powered Filename Generation (OpenAI)
Our app offers the ability to automatically generate filenames from the content of scanned documents using artificial intelligence. When you use this feature, the OCR text of the first page of the scanned document is transmitted to the servers of OpenAI, Inc. (San Francisco, USA).
Data transmitted:
- OCR text (recognized text) of the first page of the document
- Your naming rules configured in the app (filename template)
Data not transmitted: The document file itself (PDF/image), your personal data, device identifiers, or location data.
Purpose: Automatic extraction of metadata (date, sender, subject) from the document text for generating a structured filename.
Legal basis: Contract performance (Art. 6 para. 1 lit. b GDPR), as the AI filename generation is a feature actively used by you. The use of this feature is voluntary — you can also assign filenames manually.
Note: Please be aware that the OCR text of your documents may contain personal or sensitive information (e.g., names, addresses, amounts from invoices or contracts). When you use the AI filename generation, this information is transmitted to OpenAI. For information on data transfers to the USA, see the section Data Transfer to Third Countries.
Further information on data protection at OpenAI can be found in OpenAI’s Privacy Policy. OpenAI processes data submitted via the API in accordance with the OpenAI Business Terms and does not use API data for training its models.
Cloud Synchronization Between Devices
PDF Content Search offers the ability to synchronize documents between your iOS and macOS devices. When you activate this feature, your documents are transferred via our own synchronization server.
Data transmitted:
- Complete document files (PDFs/images)
- Filenames and folder structure
- Synchronization metadata (timestamps, change status)
Server location: Our synchronization servers are operated on own infrastructure of Jürgen Koller Software GmbH in Germany.
Encryption: Data transfer is conducted exclusively via encrypted HTTPS connections. Access authorization is handled through symmetrically encrypted folder tokens.
Storage duration: Your synchronized documents remain on the server as long as the associated shared folder is active. When you delete a shared folder or unpair all devices, the associated data is removed from the server.
Legal basis: Contract performance (Art. 6 para. 1 lit. b GDPR). Synchronization is a feature actively set up by you and required for cross-device usage.
Device Pairing
To set up cloud synchronization, a one-time pairing process between your devices is required. The following data is collected during this process:
- Device name (e.g., “Max’s iPhone”)
- Device type (iOS or macOS)
- A unique device ID for assignment
This data is used exclusively for managing the synchronization. You can remove paired devices at any time in the app, which will delete the associated device data.
Background Processing
The app uses iOS background processing to complete pending file uploads for cloud synchronization. This only applies to files that you have actively shared for synchronization.
PDF.Scanner. for Android
The app PDF.Scanner. (Google Play, package name software.juergenkoller.namesandnumbers) is our Android edition of the document scanner. Scanning, text recognition (OCR), and full-text search take place locally on your device. For AI-powered filename generation, the processing described above under “AI-Powered Filename Generation (OpenAI)” applies accordingly; OCR text is only transmitted to OpenAI when you actively trigger this feature. If you use the optional cross-device synchronization, the processing described above under “Cloud Synchronization Between Devices” and “Device Pairing” applies accordingly.
In-app purchases via Google Play (AI Credits). Within PDF.Scanner., paid credit packages (“AI Credits”) for the AI features can be purchased. Payment is processed exclusively via Google Play (provider: Google Ireland Limited); we do not receive any payment, card, or account data. To unlock the purchased credits, the app transmits the purchase token issued by Google and the product identifier to our server. The server verifies the purchase via the Google Play Developer API and credits the balance to your pseudonymous device identifier.
Data transmitted:
- Purchase token and product identifier of the purchased package
- A pseudonymous device identifier generated randomly at installation
Pseudonymous device identifier: Credits and purchases are assigned via an identifier generated randomly at installation. It is not the advertising ID and not your Google account; no registration or sign-in is required.
Legal basis: Contract performance (Art. 6 para. 1 lit. b GDPR) for providing the purchased credits, and our legitimate interest in preventing abuse and fraud (Art. 6 para. 1 lit. f GDPR) for the server-side purchase verification. Google’s Privacy Policy additionally applies to the payment processing by Google.
Storage duration: The data stored for credit and purchase management is retained for the duration of credit usage and within the statutory retention periods (in particular tax and commercial law obligations for purchase receipts); the information in the section “Retention Periods and Backup Storage” applies in addition. You can request deletion of the data stored for your device identifier via the contact details provided in the Legal Notice (Impressum).
No advertising, no analytics: PDF.Scanner. contains no advertising and no third-party tracking, analytics, or crash-reporting services.
Inkra: AI Writing Assistance
Inkra is a Markdown editor with optional AI assistance (e.g., proofreading, shortening, expanding, translating). The AI features are optional; without using them, your document content does not leave your device through this feature. When you trigger an AI action, the relevant text (the entire document or the selected portion) is transmitted to the AI provider you have chosen:
- Inkra KI (default): processing on Jürgen Koller Software GmbH’s own infrastructure in Germany.
- Anthropic (Claude): transmitted to Anthropic PBC, USA. For data transfers to the USA, see the section Data Transfer to Third Countries.
- OpenAI: transmitted to OpenAI, Inc., USA. For data transfers to the USA, see the section Data Transfer to Third Countries.
- Ollama (local): processing takes place entirely on your own device or your configured local instance; no data is transmitted to us or third parties.
Legal basis: Contract performance or your consent (Art. 6 para. 1 lit. b or lit. a GDPR); using the AI features is optional and actively triggered by you.
Storage of credentials: Any API keys (for Claude/OpenAI) and license keys you enter are stored exclusively locally and encrypted in your device’s Apple Keychain and are not transmitted to us.
Note: The transmitted text may contain personal or sensitive information. When using a cloud provider (Inkra KI, Claude, OpenAI), this information is transmitted accordingly. Choose Ollama if you do not want processing to leave your device.
Inkra: Document Synchronization Between Mac and iPad
Inkra offers the ability to synchronize documents between a Mac and an iPad. When you set up this feature, the shared documents are transferred via our own synchronization server.
Transmitted data:
- The complete document content (Markdown/text files)
- File and folder names and the folder structure of the sync folder
- Synchronization metadata (timestamps, change status)
Server location: Our synchronization servers are operated on own infrastructure of Jürgen Koller Software GmbH in Germany.
Encryption: Data transmission occurs exclusively over encrypted HTTPS connections. Access authorization is handled via symmetrically encrypted folder tokens.
Device pairing: Setup involves a one-time pairing process on the local network (device discovery via Bonjour), during which the device name, device type, and a unique device ID are collected for association. You can remove paired devices at any time in the app, which deletes the associated device data.
Background processing: On the iPad, Inkra uses background processing to complete pending file uploads for synchronization — only for files you have actively shared for synchronization.
Storage duration: Synchronized documents remain on the server as long as the associated shared folder is active. When you delete the shared folder or unpair all devices, the associated data is removed from the server.
Legal basis: Contract performance (Art. 6 para. 1 lit. b GDPR). Synchronization is a feature actively set up by you and required for cross-device usage.
In-App Feedback and Support (PDF Content Search, Inkra, Nemeton, Distill, FreezeText)
In our Mac and iPad apps, “Feedback & Support” in Settings lets you report bugs, request features, ask questions, or raise a billing matter.
What is transmitted: your text, the chosen category, optionally your e-mail address (only if you enter it), and the details shown beneath the form: app version, build, operating system version, distribution channel, and, where the app holds a license, its status. In apps with a customer account (Nemeton), the report is associated with your account. No device or advertising identifier is transmitted.
Where: to our support service on infrastructure operated by Jürgen Koller Software GmbH in Germany. A ticket is created there; status and replies from support are shown in the app. No data is passed on to third parties.
On your device: the app stores your sent reports with replies and an unsent draft in the app’s data area (on iPad part of the device backup), and the ticket’s access token in the keychain. You can remove both in the app via “Clear history”.
Legal basis: performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR) for purchase or license matters; otherwise our legitimate interest in fixing bugs and improving the product (Art. 6(1)(f) GDPR).
Deletion: after sending, a ticket number is shown to you. With this number you can request deletion of the ticket at any time via datenschutz@juergenkoller.software; otherwise we delete tickets after they are closed and the statutory retention periods have expired.
SolarPulse: Monitoring and Control of Balcony Solar Systems
SolarPulse consists of a web interface, an app for iPhone and iPad, and a small device for your home network, the hub. The hub reads your inverter over the local network and transmits the readings to our service so that you can view and control your system while away from home.
Account and sign-in
Sign-in is handled by our own account portal at account.juergenkoller.software. SolarPulse creates no accounts and stores no password; it only receives an identifier, your email address, your role and your language setting from the portal.
System data
For each system we store the hub’s serial number and the hardware identifier of its processor, the serial number, model and firmware version of your inverter, the system name you choose, your inverter’s settings and, if you connect a compatible electricity meter, its address on your home network. If you enter prices for your electricity tariff, we store those as well.
Readings
The hub reads your system every 0.5 seconds and transmits average, minimum and maximum values at 10-second intervals. These include generation, battery charge level, grid import and grid export. If you have connected an electricity meter, they also include the power at your house connection, that is, your household’s total consumption.
Please note: a consumption record at this time resolution allows conclusions about your daily routine, such as presence, sleeping hours or absence during holidays. We process this data solely to display your system to you, to raise alerts and to find faults. No profiling for advertising purposes and no disclosure to third parties takes place. The legal basis is the performance of our contract with you (Art. 6(1)(b) GDPR).
Retention
We store readings without a fixed deletion period so that your system history remains permanently available to you; that is the purpose of the service. You may request deletion at any time, see below. Diagnostic reports from the hub (crash reports) are deleted automatically after 7 days, at most 100 per device.
Control and logging
When you control your system through SolarPulse, we log every change with the time, the action, the old and new value, your identifier, your email address and your IP address. This log serves to make interventions in a device that feeds electricity into your home traceable, and to find faults. Only those who may control the system themselves can view it; the email address and IP address are visible to the system’s owner only. The legal basis is our legitimate interest in traceable and safe operation (Art. 6(1)(f) GDPR).
Sharing and invitations
You can invite other people to your system by entering their email address; we then send an invitation email which also names your own email address as the sender of the invitation. The invitation expires after the period you choose.
Alternatively you can create a share link. Anyone holding it sees an overview of your system with its name and current readings, but no contact details and no control log. We log when and how often a share link was used. You can revoke it at any time.
Notifications
If you enable notifications on your mobile device, the app transmits a device identifier (push token) to us. For delivery we use Firebase Cloud Messaging provided by Google Ireland Limited; this identifier and the content of the notification are transmitted to Google and may reach the USA in the process. The notification contains the name or serial number of your system and, depending on the occasion, a reading such as the battery charge level. The legal basis is your consent, which you may withdraw at any time in your device’s system settings (Art. 6(1)(a) GDPR). For transfers to the USA see the section “Data Transfer to Third Countries”.
The hub on your home network
To set it up, you transmit your Wi-Fi name and password to the hub via Bluetooth. The hub does not store the password in clear text but converts it into a derived key and stores only that; it is not transmitted to us. What remains on the hub is the Wi-Fi name, the addresses of the devices detected on your network and its own credentials for our service. The hub keeps readings in memory; only if our servers are unreachable for more than ten minutes does it write them temporarily to its memory card and delete them again after transmission.
The hub also regularly sends us an extract of its technical logs. These logs may contain network identifiers such as your Wi-Fi name or local IP addresses.
Remote maintenance
To assist you in case of a fault, we can send the hub a fixed list of diagnostic commands remotely. There is no command-line access to your device; shipped devices have no SSH access. Depending on the command, the responses contain your Wi-Fi name, the local IP addresses and name servers of your network, the hub’s system load and extracts of its logs. Every call is logged with the time, action, result and the email address of the person who triggered it; we retain these logs and delete them at your request. The legal basis is our legitimate interest in resolving faults (Art. 6(1)(f) GDPR).
Servers and service providers
The application, the database and the logs run on hardware operated by Jürgen Koller Software GmbH in Germany. When you open the web interface, your IP address appears in the server logs. For sending invitation emails we use the mail server of Strato AG. No web analytics take place in SolarPulse; no analytics or tracking services are integrated.
Data export
You can download your readings yourself at any time as a CSV, JSON or Excel file. The export contains the system name and serial number as well as the readings you selected.
Access and erasure
For access, rectification, restriction, portability and erasure of your SolarPulse data, a message to datenschutz@juergenkoller.software is sufficient. At your request we delete your system and reading data together with the associated logs. If you are only a member of someone else’s system, we remove your membership and your details from its logs; the system’s own logs remain with its owner.
SolarPulse: Error Reports and Feedback
In the SolarPulse application (web and apps) you can report a problem or suggest an improvement using the feedback button.
Always transmitted: your description, the page you were on, details about your browser and screen size and, if you are signed in, your user ID.
Only if you tick “attach diagnostic data”: technical recordings of the last few minutes, namely the application’s console output, your browser’s most recent requests to our servers including response headers, changes to cookies, and the names of locally stored settings. The box is unticked by default; without the tick, none of this is transmitted.
Automatic redaction: before sending, the application replaces recognisable email addresses, phone numbers, IBANs, access tokens and authentication headers with a placeholder. Redaction is pattern-based and therefore cannot catch every individual case.
Recording without your involvement: in two cases the application records a technical report of the scope described above on its own, without free text and without you reporting anything: when a sign-in or the renewal of your session fails, and when your session is lost although it should still be valid. The second case is limited to at most one recording per day and device. The sole purpose is to find silent sign-in faults that would otherwise go unnoticed. The legal basis is our legitimate interest in a working and secure sign-in process (Art. 6(1)(f) GDPR); you may object to this processing under Art. 21 GDPR.
Storage location and retention: reports are stored on infrastructure operated by Jürgen Koller Software GmbH in Germany and are deleted automatically after 30 days. They are not passed on to third parties.
Legal basis: your consent for the diagnostic attachment (Art. 6(1)(a) GDPR), otherwise our legitimate interest in fixing faults (Art. 6(1)(f) GDPR). You may withdraw your consent at any time with effect for the future by not ticking the box on future reports.
Deletion: after sending, a ticket number is shown to you. Using this number you can request deletion of the report at any time at datenschutz@juergenkoller.software.
7. Payment Processing via Stripe
Purchases in our web store at store.juergenkoller.software are processed through the payment
service provider Stripe.
Provider: The contracting party for the payment services is
Stripe Payments Europe, Limited
One Wilton Park, Wilton Place
Dublin 2, D02 FX04
Ireland
(registered in the Irish commercial register under number 513174)
For the execution of payment services in the European Economic Area, Stripe Technology Europe, Limited, 1 Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland is additionally involved; it is authorized as an e-money institution by the Central Bank of Ireland under reference number C187865. Technical parts of the processing are carried out by Stripe, LLC, 354 Oyster Point Boulevard, South San Francisco, California 94080, USA (see “Transfer to the USA” below).
How the payment process works. When you place your order, we redirect you to a payment page
operated by Stripe at checkout.stripe.com. You enter your payment data there, directly with
Stripe. Card numbers, bank details, and comparable payment data never reach our systems. No
scripts or other content from Stripe are embedded on our own pages.
Categories of data processed: In connection with the payment process, Stripe processes in particular:
- name and email address,
- billing address and country,
- the VAT identification number, if you provide one,
- payment data (card details, bank details, information on the payment method chosen),
- amount, currency, time, and the identifiers of the payment and the checkout session,
- IP address, device and browser details for detecting fraudulent payments.
What we receive from it. From Stripe we receive the payment status, the identifiers of the checkout session and of the payment, the amount and currency, your email address, and the details required for the tax treatment and for invoicing (name, billing address, country, and where applicable the VAT identification number).
Purposes: Processing your payment, reversing it in the event of a withdrawal or a refund, handling chargebacks, determining the applicable VAT, creating and retaining purchase and invoice records, and preventing fraud and abuse.
Legal basis:
- Contract performance (Art. 6 para. 1 lit. b GDPR) for processing and reversing the payment.
- Compliance with a legal obligation (Art. 6 para. 1 lit. c GDPR) for the tax treatment and the retention of records, in particular under § 14b and § 22 UStG, § 147 AO, and § 257 HGB.
- Legitimate interest (Art. 6 para. 1 lit. f GDPR) in preventing fraud and payment defaults, for the fraud detection.
Stripe’s role. Stripe processes part of the data on our behalf; to that extent the requirements of Art. 28 GDPR on processing on behalf of a controller apply. For another part — in particular fraud prevention and compliance with its own regulatory, anti-money-laundering, and tax obligations — Stripe is a controller in its own right. Stripe’s privacy policy applies to that part.
Transfer to the USA. As part of the payment processing, data is also transferred to Stripe, LLC in the USA. The USA has an adequacy decision from the European Commission pursuant to Art. 45 GDPR (EU-U.S. Data Privacy Framework); Stripe states that Stripe, LLC is certified under this framework. In addition, Stripe provides EU Standard Contractual Clauses as appropriate safeguards pursuant to Art. 46 para. 2 lit. c GDPR for transfers from the European Economic Area, which also hold if the adequacy decision were to lapse.
Storage duration: We retain the purchase and payment data arising on our side for the duration of the contractual relationship and beyond that within the statutory retention periods; for details see the section “Retention Periods and Backup Storage”. Stripe’s privacy policy applies to the storage duration at Stripe.
Further information: Stripe’s Privacy Policy · Stripe’s Data Privacy Framework statement
8. Data Transfer to Third Countries
As part of the AI-powered filename generation (see the section Data Processing in Our Apps), when using Inkra’s AI writing assistance with the provider OpenAI, and when using the AI product assistant (see the section AI Product Assistant), data is transmitted to OpenAI, Inc. in the USA. Since July 10, 2023, the USA has had an adequacy decision from the European Commission pursuant to Art. 45 GDPR (EU-U.S. Data Privacy Framework). OpenAI is certified under the EU-U.S. Data Privacy Framework, ensuring an adequate level of data protection.
Additionally, we have concluded a Data Processing Agreement (DPA) with OpenAI that meets the requirements of Art. 28 GDPR and includes EU Standard Contractual Clauses (SCCs) pursuant to Art. 46 para. 2 lit. c GDPR.
When using Inkra’s AI writing assistance with the provider Anthropic (Claude), data is transmitted to Anthropic PBC in the USA. The transfer is based on appropriate safeguards pursuant to Art. 46 GDPR (EU Standard Contractual Clauses) or — to the extent the provider is certified under it — the EU-U.S. Data Privacy Framework (Art. 45 GDPR). Use of Anthropic is optional; you may instead choose the “Inkra KI” provider operated in Germany or fully local processing via Ollama.
For purchases in our web store, data is transferred to Stripe, LLC in the USA as part of the payment processing. The transfer is based on the adequacy decision of the European Commission pursuant to Art. 45 GDPR (EU-U.S. Data Privacy Framework), under which Stripe, LLC is certified according to Stripe’s own statement, and additionally on the EU Standard Contractual Clauses pursuant to Art. 46 para. 2 lit. c GDPR that Stripe provides for transfers from the European Economic Area. For details, see the section “Payment Processing via Stripe”.
For purchases via the Mac App Store, Apple handles the purchase on its own responsibility; the contracting party is Apple Distribution International Ltd., based in Ireland. We receive no personal purchase data in this context. Apple’s privacy policy applies to the processing by Apple, including any transfer to the USA.
All other data processing — the cloud synchronization, the account and license management, and the local processing in our apps — takes place exclusively in Germany or on your device. No transfer to third countries occurs in these cases.
9. Your Rights
You have the following rights regarding your personal data:
- Right to information (Art. 15 GDPR)
- Right to correction (Art. 16 GDPR)
- Right to deletion (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to revoke consent (Art. 7 para. 3 GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
To exercise these rights, please contact us at: datenschutz@juergenkoller.software