Privacy Policy
Version 2026-08-07 — courtesy translation; the German version (Datenschutzerklärung) is legally binding.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is: David Matthias Hübscher, Mittelstr. 12, 52379 Langerwehe, Germany. Email: contact@air-node.net. Contact form: https://air-node.net/en/kontakt. (Sole proprietor.) This policy applies to the app (app.air-node.net) and the website (air-node.net).
2. Data protection officer
A data protection officer is not required under Art. 37 GDPR / § 38 BDSG and has not been appointed. Please address data protection enquiries to contact@air-node.net.
4. Your rights as a data subject
Under the GDPR you have the following rights: access (Art. 15) to the data stored about you; rectification (Art. 16) of inaccurate data; erasure (Art. 17) — the "right to be forgotten"; restriction of processing (Art. 18); data portability (Art. 20) — your data in a structured, commonly used, machine-readable format; objection (Art. 21) to processing based on legitimate interests; withdrawal of consent (Art. 7(3)) with effect for the future.
Some of these rights can additionally be exercised directly through the functions of your account in the app (data export § 5.12, account settings, account deletion § 6). An informal message to contact@air-node.net suffices. We handle requests within one month (up to three months in exceptional cases), free of charge; we may verify your identity.
5. Processing activities in detail
For each activity we state the data processed, the purpose, the legal basis, and the retention period.
5.1 Provision of the website and the app
Data: technical connection data (IP address, timestamp, requested path, status code). The app and API are served from our infrastructure in the EU (Oracle Cloud, Frankfurt). Access logs of the serving infrastructure are collected centrally and deleted automatically after at most 48 hours; the air-node.net website itself does not log accesses. In the API, the IP address is additionally used only transiently in memory for rate limiting (abuse protection) and is not stored there. Cloudflare provides only the DNS service for air-node.net and does not proxy app/API traffic.
Purpose: delivery, stability and security of the service (including error and abuse analysis). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning service). Retention: infrastructure access logs at most 48 hours; beyond that, IP addresses are not stored.
Status indicator: the status indicator on the website additionally calls an interface of our platform when a page loads, to display the platform's measured operational status. That request goes to the same EU infrastructure described above and is handled the same way (access logs for at most 48 hours; the IP address is used only transiently in the API for rate limiting). Nothing is stored on or read from your device for this, so no consent under § 25 TDDDG is required.
5.2 Registration and user account
Data: email address, password (stored only as a cryptographic hash, never in plain text), verification status, role, creation/deactivation timestamps. Purpose: provision of the user account and contractual services. Legal basis: Art. 6(1)(b) GDPR (contract). The email address is verified via a confirmation link (double opt-in).
Acknowledgement of this privacy policy: creating an account (registration as well as first-time sign-in via a third-party provider, § 5.3) requires confirming that you have read this privacy policy. For accountability (Art. 5(2) GDPR) we store the acknowledged version (version date) and the UTC timestamp of the confirmation with the account. This is an acknowledgement, not consent; the legal basis remains Art. 6(1)(b) GDPR.
Retention: for the lifetime of the account; after deletion see § 6.
5.3 Third-party sign-in (SSO: Google, Microsoft, GitHub)
Data: a stable provider-side user identifier and the email address transmitted by the provider.
Important (§ 25 TDDDG): sign-in with a provider starts only after you actively click the respective sign-in button. Only then does a redirect to the provider or the loading of a provider script take place. Without your action, no embedding and no data transfer to the providers takes place.
Purpose: convenient sign-in without a separate password. Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps/sign-in at your initiative). Recipients/third country: Google, Microsoft, GitHub (USA) — see § 7. Retention: as long as the link or the account exists.
5.4 Device management and pairing
Data: device id/serial number, the device name you assign (may e.g. name a room), pairing records. Purpose: assignment and control of your AirNode devices. Legal basis: Art. 6(1)(b) GDPR. Retention: for the lifetime of the account or device assignment; the history of individual control commands (e.g. fan override, restart) is deleted automatically after 90 days — only the most recently acknowledged settings command is kept as the current device state.
5.5 Measurements (telemetry)
Data: temperature, humidity and derived readings with timestamps, stored per device id (linkable to a person only indirectly via device ownership). Purpose: display, history, control and alerting. Legal basis: Art. 6(1)(b) GDPR.
Retention: raw data 90 days (automatic retention policy); hourly aggregates 12 months; daily aggregates 10 years. On account deletion, measurements including aggregates are erased (§ 6).
5.6 Alerts and notifications
Data: alert events, notification preferences (email/push per alert type). Purpose: notifying you of relevant conditions (e.g. device failure). Legal basis: Art. 6(1)(b) GDPR; optional notification categories Art. 6(1)(a) GDPR (consent).
Push notifications (Firebase Cloud Messaging): an FCM registration token is processed only if you enable push notifications in an app (legal basis: Art. 6(1)(a) GDPR, consent). Actual push delivery via Google (USA) is currently not active; the recipient would then be Google, see § 7.
5.7 Transactional email
Data: recipient address, subject, content (e.g. verification, password reset, email change, alert mails). Purpose: performance of the contract and account security. Legal basis: Art. 6(1)(b) GDPR (or (f) for security mails). Processor: Resend (email delivery provider) — see § 7. Retention: send records are kept for 30 days after delivery and then deleted; the email content is removed from the sending system as early as 48 hours after delivery (leaving only recipient, subject and delivery status).
5.8 Contact form (air-node.net)
Data: your email address and message (name optional). Purpose: handling your enquiry. Legal basis: Art. 6(1)(b) GDPR (where contract-related) or Art. 6(1)(f) (interest in answering enquiries). Anti-spam: privacy-friendly (honeypot) — no Google reCAPTCHA, no third-party scripts.
Retention: deletion once your enquiry is finally resolved. The message forwarded to us also remains in the sending system for up to 30 days (§ 5.7).
5.9 API keys
Data: key name and hash, assignment to the account. Purpose: programmatic access to your own data. Legal basis: Art. 6(1)(b) GDPR. Retention: until revocation or account deletion.
5.10 Administration and audit logs
Data: logged administrative actions (admin id, action, target, time). Purpose: security, traceability, accountability (Art. 5(2) GDPR). Legal basis: Art. 6(1)(f) GDPR. Retention: 12 months; on account deletion the personal reference is removed (pseudonymisation instead of deletion where required for accountability).
5.11 Security / abuse protection
Data: IP address (transient only, see § 5.1); device connection data (device connections are logged with the device identifier and connection IP). Purpose: abuse protection, rate limiting, operating the device connection. Legal basis: Art. 6(1)(f) GDPR. Retention: IP only transient or in infrastructure access logs for at most 48 hours (§ 5.1); device connection logs at most 30 days (rotation).
5.12 Data export (self-service, Art. 15/20 GDPR)
Data: on your request we create an export archive with your account, device, measurement, alert and settings data in a structured, commonly used, machine-readable format. Credentials, passwords and keys are not included. Purpose: fulfilling your rights of access and data portability. Legal basis: Art. 6(1)(c) GDPR in conjunction with Art. 15, 20 GDPR.
Storage/recipients: the archive is stored encrypted in EU object storage (Oracle, Frankfurt) and can be downloaded only while signed in to your account; the link in the notification email leads into the app. Retention: export archives are deleted automatically 7 days after provision; immediately on account deletion.
5.13 Device operating diagnostics
Data: one state snapshot per device with technical operating values — memory and connection utilisation, uptime since the last restart, radio signal strength, reset reason, and the timestamp of the last update. Stored per device id; the personal reference arises indirectly through the device being assigned to your account. Individual values can permit inferences about your household — the reset reason and uptime about power cuts, the signal strength about changes in the living environment.
Purpose: showing you your device's state, diagnosing a fault on your device, and technically providing the remote functions — that is, the diagnostic function of the service owed to you. Legal basis: Art. 6(1)(b) GDPR. Provider-side monitoring of platform stability and abuse protection are separate and described in § 5.11; they rest on Art. 6(1)(f) GDPR. Retention: for the duration of the device assignment. No history is kept — the snapshot is overwritten on every update; only the most recently reported state is stored. On account deletion see § 6.
6. Account deletion
You can request deletion of your account at any time in the app. Deletion runs with a 14-day grace period: during this time you can cancel the request in the app; all active sessions are signed out when the request is made. After the period expires, all associated personal data is erased (account, tokens, API keys, device data, measurements including history aggregates, alerts, settings, data-export archives). Where statutory retention duties or overriding security/accountability interests exist (e.g. audit logs), the data is pseudonymised instead (Art. 17(3) GDPR). You receive a final confirmation by email. The grace period protects against accidental or abusive deletion. Backups: for resilience we create daily database backups (stored encrypted in the EU, Oracle Frankfurt; kept at most 30 days). Deleted data may persist in these backups for up to 30 days; backups are never restored into live systems except for disaster recovery — in that case, deletions made in the interim are re-applied.
7. Recipients and international transfers
We use carefully selected processors (Art. 28 GDPR): Oracle Cloud Infrastructure (hosting, database, object storage; data residency EU/Frankfurt, Oracle America DPF-certified); Resend (transactional email delivery; USA, DPF-certified); Cloudflare (DNS service for air-node.net, forwarding of our contact addresses, access protection for internal administration interfaces — not user-facing; USA, DPF-certified); 1&1 Mail & Media (web.de) (mailbox receiving our forwarded contact addresses; Germany).
When you sign in via Google, Microsoft or GitHub (§ 5.3), these providers receive data as independent controllers (USA, each DPF-certified); Google would additionally become a recipient if push delivery is activated in the future (§ 5.6).
All US recipients named above are certified under the EU-US Data Privacy Framework; transfers rest on the European Commission’s adequacy decision (Art. 45 GDPR), supplemented by standard contractual clauses (SCCs) in the respective data processing agreements. DPF status is re-verified regularly.
9. No automated decision-making
No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.
10. Necessity of providing data
Using the service requires the data necessary for the account and performance of the contract (in particular an email address). Without this data the service cannot be provided. Optional information is marked as such.
11. Version / changes
This privacy policy is dated (version) 2026-08-07. The version date is also the identifier we store as acknowledgement evidence when an account is created (§ 5.2). We update this policy when processing or the legal situation changes. For future substantial changes (in particular new purposes, new recipients or extended retention periods) we will additionally notify registered users actively by email.