With this privacy policy, we inform you in accordance with Art. 13 and 14 GDPR about the processing of personal data associated with visiting our website www.trawa.de, using our customer portal at portal.trawa.de, and the initiation and execution of electricity supply and other business relationships with us.
1. Controller
The controller within the meaning of Art. 4 No. 7 GDPR is:
Future Energy Services GmbH
Hohenzollerndamm 54a
14199 Berlin
Germany
Phone: 030 43971424
Email: info@trawa.de
Website: www.trawa.de
If you have any questions regarding the processing of your personal data or the exercise of your rights, you can contact us at any time, in particular at datenschutz@trawa.de. Our data protection officer can be reached via heyData GmbH, Schützenstraße 5, 10117 Berlin, Germany, email: datenschutz@heydata.eu.
2. Rechtsgrundlagen, Speicherdauer und Empfänger
Soweit wir bei den einzelnen Verarbeitungen keine speziellere Rechtsgrundlage benennen, beruht die Verarbeitung auf Art. 6 Abs. 1 UAbs. 1 lit. a DSGVO (Einwilligung), lit. b (Vertrag und vorvertragliche Maßnahmen), lit. c (rechtliche Verpflichtungen, insbesondere handels-, steuer- und energiewirtschaftliche Vorgaben) oder lit. f (berechtigte Interessen). Besondere Kategorien personenbezogener Daten (Art. 9 DSGVO) verarbeiten wir im Rahmen der Website-Nutzung und der gewöhnlichen Geschäftsbeziehung mit unseren Geschäftskunden nicht.
Wir verarbeiten personenbezogene Daten nur so lange, wie es für die jeweiligen Zwecke erforderlich ist oder wir gesetzlich zur Aufbewahrung verpflichtet sind. Handels- und steuerrechtlich relevante Unterlagen bewahren wir nach Maßgabe der §§ 257 HGB, 147 AO auf (Handelsbücher, Inventare, Eröffnungsbilanzen, Jahresabschlüsse zehn Jahre, Buchungsbelege acht Jahre, Handels- und Geschäftsbriefe sechs Jahre). Energiewirtschaftliche Verbrauchs- und Abrechnungsdaten werden entsprechend den Vorgaben des EnWG, des MsbG und der einschlägigen Festlegungen der Bundesnetzagentur gespeichert. Daten zur Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen werden bis zum Eintritt der Verjährung (regelmäßig drei Jahre, in Einzelfällen bis zu dreißig Jahren) sowie etwaiger nachfolgender Verfahren aufbewahrt. Einwilligungsbasierte Verarbeitungen führen wir bis zum Widerruf der Einwilligung fort; eine weitergehende Speicherung erfolgt nur, soweit hierfür eine andere Rechtsgrundlage besteht, insbesondere zur Dokumentation des Widerrufs, zur Wahrung von Sperrlisten oder zur Erfüllung gesetzlicher Aufbewahrungspflichten.
Setzen wir externe Dienstleister ein, die personenbezogene Daten in unserem Auftrag verarbeiten, schließen wir mit diesen einen Vertrag zur Auftragsverarbeitung nach Art. 28 DSGVO. Eine Übersicht der Empfängerkategorien finden Sie in Ziffer 14; zu Drittlandübermittlungen siehe Ziffer 15.
3. Provision of the website and server log files
Each time our website is accessed, technical data (in particular IP address, date and time of access, retrieved file, referrer URL, browser and operating system information, as well as the amount of data transferred) is temporarily stored in server log files. This processing is carried out for the technical provision of the website and to ensure IT security on the basis of Art. 6 Para. 1 Subpara. 1 lit. f GDPR. Log file entries are stored for up to thirty days and are then deleted or anonymized; they are not merged with other personal data.
4. Cookies and similar technologies
We use cookies and comparable technologies (such as local storage, pixels, and scripts) on our website. Strictly necessary technologies – in particular for the provision of the functions you actively request – are set on the basis of Section 25 (2) No. 2 TDDDG without consent; the subsequent processing of the data collected thereby is carried out on the basis of Art. 6 (1) subpara. 1 lit. b or lit. f GDPR. The use of all other technologies, in particular for analysis, marketing, and targeting purposes, is carried out exclusively on the basis of your consent in accordance with Section 25 (1) TDDDG and Art. 6 (1) subpara. 1 lit. a GDPR.
We obtain consent via the consent management tool of Usercentrics GmbH (Sendlinger Straße 7, 80331 Munich) before the corresponding technologies are activated. You can withdraw your consent at any time with effect for the future, without affecting the lawfulness of the processing carried out up to the time of withdrawal. You can declare your withdrawal at any time via the cookie settings on our website and adjust your selection.
The current overview of all cookies and comparable technologies used – including provider, purpose, legal basis, storage period, and any third-country context – can be found in our consent management tool under the cookie settings.
5. Contact
If you contact us via the contact form, by email, by telephone, or via other communication channels, we will process the personal data you provide (in particular your name, company, function, telephone number, email address, and the content of your inquiry) to respond to your inquiry, to process requests for offers and consultations, and to initiate and maintain any subsequent business relationship. The legal basis is Art. 6 para. 1 subpara. 1 lit. b GDPR, insofar as you yourself are a potential contracting party, otherwise Art. 6 para. 1 subpara. 1 lit. f GDPR; our legitimate interest lies in professionally responding to inquiries and developing our B2B business relationships.
6. Newsletter
With the trawa newsletter, we provide information about developments in the energy market as well as our products and events. To receive it, a valid email address must be provided; any additional information is voluntary. We use the double opt-in procedure and record the registration time, confirmation time, and IP address for evidentiary purposes. The legal basis is Art. 6 para. 1 subpara. 1 lit. a GDPR in conjunction with Sec. 7 para. 2 no. 3 UWG (German Act Against Unfair Competition); for promotional communication to existing customers, additionally Art. 6 para. 1 subpara. 1 lit. f GDPR in conjunction with Sec. 7 para. 3 UWG. We handle distribution via Brevo (Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France). The provider processes personal data on our behalf based on a data processing agreement pursuant to Art. 28 GDPR. You can unsubscribe at any time via the unsubscribe link in each newsletter issue or informally using the contact details mentioned above. To evaluate the reach of our newsletter, we analyze personal open and click behavior; the legal basis for this is your consent given as part of the newsletter registration in accordance with Sec. 25 para. 1 TDDDG (German Act on Data Protection and Privacy in Telecommunications and Telemedia) and Art. 6 para. 1 subpara. 1 lit. a GDPR, which you can revoke at any time with effect for the future.
7. Events, Trade Fairs, and Webinars
If you register for an event, a webinar, or a trade fair appearance in which we participate or which we host, we process the registration data (specifically name, company, position, email address, and phone number) to organize and conduct the event, as well as to communicate with you before and after. The legal basis is Art. 6 para. 1 subpara. 1 lit. b GDPR, provided you are a party to the contract yourself; otherwise, Art. 6 para. 1 subpara. 1 lit. f GDPR applies. For image or sound recordings as well as video recordings, we obtain separate prior consent in accordance with Art. 6 para. 1 subpara. 1 lit. a GDPR. For webinars and online events, we use the Zoom platform of Zoom Video Communications, Inc. (55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA). The provider processes personal data on our behalf based on a data processing agreement pursuant to Art. 28 GDPR. For transfers to the United States of America, please see Section 15.
8. Initiation and implementation of electricity supply
As part of our business activities as an electricity supplier, we process personal data of our business customers as well as their contact persons and other representatives. In particular, we process master data of the contractual partner (company name, legal form, address, commercial register, VAT identification number) as well as the authorized and operational contact persons (name, function, professional contact details), consumption and delivery point data (market location and metering location IDs, meter numbers, meter readings, load profiles, consumption profiles, delivery and supply points), contract data (subject of the contract, term, conditions, procurement preferences, PPA structures), billing and payment data (bank details, SEPA mandate, invoices, incoming payments, and, if applicable, dunning processes) as well as communication and correspondence data from the ongoing business relationship. Consumption, metering and delivery point data generally relate to the respective delivery point or company; however, they may be personal to the extent that they can be assigned to an identified or identifiable natural person.
Insofar as processing concerns natural persons as contractual partners, it is based on Art. 6 para. 1 subpara. 1 lit. b GDPR; insofar as contact persons or other representatives of business customers are affected, on Art. 6 para. 1 subpara. 1 lit. f GDPR. Cooperation and retention obligations under tax, commercial and energy law are based on Art. 6 para. 1 subpara. 1 lit. c GDPR. The assertion, exercise or defense of legal claims, including any transfer to debt collection service providers or lawyers, is based on Art. 6 para. 1 subpara. 1 lit. f GDPR.
As part of the preparation of offers for potential business customers, we request a possible coverage amount from Allianz Trade. For this purpose, we transmit the company name and the VAT identification number and receive back the coverage amount determined by Allianz Trade, which we take into account when making our decision about the business relationship. Insofar as this information constitutes personal data, particularly in the case of sole proprietorships, the processing is carried out on the basis of Art. 6 para. 1 subpara. 1 lit. f GDPR; our legitimate interest lies in assessing and limiting the risk of default on payments. We do not receive a credit score.
The handling of electricity supply requires an electronic data exchange with other market participants, in particular grid operators, upstream suppliers, balancing group managers, metering point operators and transmission system operators. This includes in particular the business processes for customer supply with electricity (GPKE), the market rules for balancing group accounting of electricity (MaBiS), the switching processes in metering (WiM) as well as the market processes for generating market locations of electricity (MPES). The legal basis is Art. 6 para. 1 subpara. 1 lit. c GDPR in conjunction with the relevant energy industry guidelines and regulations as well as, additionally, Art. 6 para. 1 subpara. 1 lit. b and lit. f GDPR.
9. Data from third-party sources
We do not collect personal data solely directly from the data subject, but also receive it from third-party sources in the course of our business activities – in particular from grid operators, metering point operators, transmission system operators, balance responsible parties, and other market participants as part of market communication, from public registers (commercial and transparency registers), as well as from business partners and corporate customers who provide us with contact details. Within the scope of the credit assessment described in Section 8, we also receive information from Allianz Trade, to the extent that it is personal data. Insofar as we do not collect personal data directly from you, we will inform you in accordance with Art. 14 GDPR; this may be done through this privacy policy or, if necessary, through separate information on a case-by-case basis.
10. Customer Portal
Via our customer portal at portal.trawa.de, we provide our business customers in particular with analyses of their electricity supply, consumption data, and, where applicable, further functions (such as for energy management software, battery storage solutions, or intelligent system control). We process login and authentication data, master and contract data, consumption and load profile data displayed in the portal, settings made by you, as well as usage and log data (in particular IP address, user and account ID, request identifier, and request path, as well as a separate audit log for data exports) to ensure the functionality and security of the portal. The portal is operated by us and hosted in the region eu-central-1 (Frankfurt) on the infrastructure of Amazon Web Services EMEA SARL (38 Avenue John F. Kennedy, L-1855 Luxembourg); logging in, sending system-related emails, data storage, and logging also take place via AWS services (in particular Amazon Cognito, Amazon SES, and Amazon CloudWatch Logs). For error monitoring, we use Sentry (Functional Software, Inc., San Francisco, USA) with an EU ingest endpoint. To the extent that we use the Session Replay feature to record user sessions, we only activate this based on your prior consent pursuant to Section 25 (1) TDDDG and Art. 6 (1) subpara. 1 (a) GDPR. We also use Mixpanel, Inc. (USA) to analyze the usage of the customer portal. Page views and in-app events are processed via an EU endpoint; geolocation is deactivated. Mixpanel is only activated based on your prior consent pursuant to Section 25 (1) TDDDG and Art. 6 (1) subpara. 1 (a) GDPR; you can revoke this consent at any time with effect for the future. The support widget is provided via Freshworks Inc. (San Mateo, USA); for the display of location maps, we use Google Maps (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Insofar as the aforementioned providers process personal data on our behalf, the necessary data processing agreements pursuant to Art. 28 GDPR are in place; information on transfers to third countries can be found in Section 15. The legal basis is Art. 6 (1) subpara. 1 (b) GDPR, provided that you yourself are a party to the contract, and otherwise Art. 6 (1) subpara. 1 (f) GDPR. Security-relevant log data is generally stored for a period of 365 days and then deleted; longer storage only occurs to the extent necessary to investigate specific security incidents or to assert, exercise, or defend legal claims.
11. Applications and Career
We process applications for the purpose of conducting the application process and deciding on the establishment of an employment relationship (in particular cover letters, CVs, certificates, proofs of qualification, contact details, and information on previous experience). The legal basis is, in particular, Section 26 (1) of the German Federal Data Protection Act (BDSG) in conjunction with Art. 88 GDPR; insofar as processing is necessary for the implementation of pre-contractual measures, additionally Art. 6 (1) subpara. 1 lit. b GDPR. Applications can be submitted via our career page or via the job advertisements on LinkedIn and Indeed. Applications from our career page and via LinkedIn are processed via the platform of our applicant management service provider Ashby, Inc. (San Francisco, USA); applications via Indeed are processed via the platform of Personio SE & Co. KG (Rundfunkplatz 4, 80335 Munich, Germany). Both providers process personal data on our behalf based on data processing agreements pursuant to Art. 28 GDPR; for third-country transfers to Ashby, please see section 15. In the event of a rejection, applicant data is generally deleted six months after completion of the process; in the event of hiring, the data is transferred to the personnel file. In addition, we maintain a talent pool in which we retain applicant profiles for a period of up to six months from the date of the original application. Before this period expires, we will ask you for your explicit consent to further storage; if you do not grant this, we will anonymize or delete your data. The legal basis for inclusion in the talent pool is Art. 6 (1) subpara. 1 lit. a GDPR.
12. Social media appearances
We maintain corporate presences on LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland), on Xing (New Work SE, Am Strandkai 1, 20457 Hamburg, Germany), on the Meta platforms Facebook and Instagram (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland), and on YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The respective providers collect and process personal data of visitors to our pages under their own responsibility; we have only limited influence on this processing. For the processing of Page Insights data, we are joint controllers with LinkedIn and Meta within the meaning of Art. 26 GDPR. The corresponding joint controller agreements can be accessed at https://legal.linkedin.com/pages-joint-controller-addendum (LinkedIn) and at https://www.facebook.com/legal/terms/page_controller_addendum (Meta for Facebook and Instagram). The legal basis for our corporate presences is Art. 6 (1) subpara. 1 (f) GDPR; our legitimate interest lies in the effective public image and targeted addressing of potential business customers, business partners, and applicants. You can assert your data subject rights both against us and directly against the respective providers.
13. Trust Center
We provide information on our information security and compliance via our Trust Center at trustcenter.trawa.de. To operate the Trust Center, we use the platform of Vanta, Inc. (655 Montgomery Street, Suite 1600, San Francisco, CA 94111, USA). On our behalf, Vanta processes in particular log data (IP address, date and time of access, pages accessed), device information (browser, operating system, device type), location information derived from the IP address, as well as usage metadata (documents accessed and downloaded). Access to the documents stored in the Trust Center is public; Vanta logs all access and document retrievals. The legal basis is Art. 6 para. 1 subpara. 1 lit. f GDPR. For the conditions of transfer to the United States of America, see Section 15.
14. Categories of Recipients
Recipients of your personal data are, in particular, processors commissioned by us (including hosting, CRM, newsletter, conference, trust center, and other IT service providers), market participants in the energy sector (grid operators, metering point operators, balance responsible parties, transmission system operators, upstream suppliers), banks and payment service providers, credit insurers within the scope of credit checks, debt collection service providers and lawyers for the assertion of claims, tax advisors and auditors, authorities and courts within the scope of legal obligations, as well as buyers and potential buyers in the context of corporate transactions.
15. Transmission to third countries
Insofar as service providers or recipients transfer personal data to countries outside the European Economic Area or process it there on our behalf, this is only done under the conditions of Art. 44 et seq. GDPR. Depending on the recipient, we rely in particular on an adequacy decision of the European Commission (Art. 45 GDPR), standard contractual clauses pursuant to Art. 46 (2) (c) GDPR (Implementing Decision (EU) 2021/914), routinely flanked by supplementary measures based on a Transfer Impact Assessment (assessment of the level of protection in the third country), or the EU-U.S. Data Privacy Framework, provided the respective recipient is certified. We only use exceptions according to Art. 49 GDPR in individual cases. Further information on the guarantees available in individual cases will be provided to you upon request.
16. Automated Decision-Making
Solely automated decision-making within the meaning of Art. 22 GDPR with legal effect or similar significant impairment for you does not take place.
Irrespective of this, we use automated optimization procedures within the scope of controlling flexible energy plants. Here, we continuously create forecasts on consumption and generation data as well as price developments, taking into account local site factors and historical energy flows, and derive control signals for the respective energy plants from this. This serves to optimize purchasing positions and electricity flows as well as to reduce the energy costs of our customers. These procedures do not constitute a solely automated decision within the meaning of Art. 22 GDPR in relation to a natural person.
17. Your rights as a data subject
If the respective legal requirements are met, you have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR) towards us, as well as the right to withdraw consent once given at any time with effect for the future (Art. 7 para. 3 GDPR), without affecting the lawfulness of the processing carried out up to the time of withdrawal. You can assert these rights using the contact details specified in Section 1. Your right to object pursuant to Art. 21 GDPR is explained separately in Section 18.
18. Right to object (Art. 21 GDPR)
INFORMATION ON YOUR RIGHT TO OBJECT UNDER ART. 21 GDPR
1. Right to object on a case-by-case basis. You have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6(1) subparagraph 1 lit. e or lit. f GDPR; this also applies to profiling based on these provisions. We will then no longer process your personal data, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves to assert, exercise, or defend legal claims.
2. Right to object to direct marketing. If we process your personal data for the purpose of direct marketing, you have the right to object to this processing at any time; this also applies to any profiling associated with it. If you object to the processing for direct marketing purposes, we will no longer process your personal data for these purposes.
3. Form of objection. The objection can be made informally and should, if possible, be addressed to: Future Energy Services GmbH, Hohenzollerndamm 54a, 14199 Berlin, or by email to datenschutz@trawa.de.
19. Right to lodge a complaint with a supervisory authority
Without prejudice to any other legal remedies, you have the right to lodge a complaint with a data protection supervisory authority pursuant to Art. 77 GDPR if you believe that the processing of personal data concerning you violates the GDPR. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59-61, 10555 Berlin, Email: mailbox@datenschutz-berlin.de.
