slunra
Back to home
Legal

Privacy policy

This policy explains what personal data Slunora processes, why, on what legal basis, and what rights you have. We follow the principle that the application never collects more than it genuinely needs to work.

Effective from 9 July 2026

1. Data controller

The data controller is Lukáš Valčo, business ID (IČO) 29596271, registered at Dražíč 95, 375 01 Dražíč, Czech Republic (the “controller”). For any privacy matters, contact us at lukas.valco@outlook.com.

2. What data we process and why

We process only the data necessary to run the service. For each purpose we state the legal basis under Art. 6 GDPR:

  • E-mail (newsletter sign-up / getting in touch) — so we can send you a check result or the information you requested. Legal basis: consent (Art. 6(1)(a)).
  • Account e-mail — running a password-free “account-lite” that links you to your connected systems. Legal basis: performance of a contract / provision of the service (Art. 6(1)(b)).
  • Inverter vendor account credentials (e.g. SolaX) — so we can read data from your solar plant at your request. We store them encrypted (AES-256-GCM) and never return them to the browser. Legal basis: provision of the service and your explicit consent.
  • Installation location (GPS), panel tilt and orientation, installed power — inputs for the diagnostic calculation and comparison against expected output (PVGIS). Legal basis: provision of the service.
  • Your plant's production data — the basis for diagnostics and monthly evaluation. Legal basis: provision of the service.
  • Record of consent given (time, text version, IP address, browser identification) — so we can demonstrate what you agreed to and when, as GDPR requires. Legal basis: compliance with a legal obligation (Art. 6(1)(c)).

3. Cookies and similar technologies

Slunora uses no analytics or marketing cookies and does not track you across sites. We determine your language from your browser settings (the Accept-Language header), not from a cookie. We do not use Google Analytics or similar tools.

4. Recipients and transfers to third parties

We use a small number of processors to run the service. We keep data preferentially within the EU:

  • Seznam.cz a.s. (Mapy.com) — when the map is shown, map tiles load from your browser, which discloses your IP address to Seznam. The map is used to pick your installation location.
  • Neon (database) — secure data storage, EU region (Frankfurt).
  • Vercel — hosting and delivery of the website.
  • PVGIS (European Commission) — from our server we send coordinates and installation parameters to calculate expected output; we send no identifying data.

5. How long we keep data

Newsletter e-mails are kept until you withdraw consent. Data tied to your account and connected systems is kept for as long as you use the service; when a system is disconnected we delete its access credentials. Consent records are kept for as long as needed to demonstrate them.

6. Your rights

In relation to your personal data you have the following rights under GDPR. You can exercise them via the controller's contact e-mail above.

  • the right of access to your data and a copy of it,
  • the right to rectification of inaccurate data,
  • the right to erasure (the “right to be forgotten”),
  • the right to restriction of processing,
  • the right to data portability,
  • the right to object to processing,
  • the right to withdraw consent at any time (withdrawal does not affect processing before withdrawal),
  • the right to lodge a complaint with the Czech Data Protection Authority (Úřad pro ochranu osobních údajů, www.uoou.cz).

7. Security

Inverter vendor account credentials are stored encrypted (AES-256-GCM) and are never sent back to the browser. Transfers happen exclusively over HTTPS. Access to data is limited to the necessary technical processing.

8. Changes to this policy

We may update this policy as the service evolves. The current version is always available on this page with its effective date.