Iskraemeco eMobility

Privacy policy

Effective date: 22 July 2025
Last updated: 22 July 2025

Who we are

Iskraemeco Portugal, Lda. (“Iskraemeco”, “we”, “us” or “our”) is a company registered at Rua Santos Pousada, N.º 157 – 4.º, Sala 17 4000–485 Porto. We operate the Iskraemeco eMobility mobile applications for iOS and Android, including the Spectre app, the eMobility web portal, and the public website https://www.iskraemeco-emobility.com (together, the “Services”).

General privacy enquiries: info.pt@iskraemeco.com

Scope of this Policy

This Policy covers personal data processed when you:

  • Visit the Site (https://www.iskraemeco-emobility.com);
  • Use any Iskraemeco eMobility App, including the Spectre App, downloaded from the Apple App Store or Google Play Store (the “App”);
  • Interact with our cloud APIs or customer support channels that link to this Policy.

If a particular service links to a different privacy notice, that notice will prevail for that service.

What data we collect

We collect only the categories shown below. If a data point is optional, we will say so when requesting it.

CategoryExamplesHow we collectPurposeRetention
Account & ContactName, e-mail, phone, postal addressYou provide in App/Site formsCreate/manage account, service messages, supportDeleted 30 days after account deletion or 24 months of inactivity
AuthenticationEncrypted password, OAuth/Apple ID/Google ID tokenWhen you sign inSecure loginDeleted with account
IdentifiersDevice ID, advertising ID (AAID/IDFA), IP, push-tokenCollected automaticallyFraud prevention, push notifications, analyticsLogs 90 days; push-token removed when you disable pushes
Precise location (GPS)Charger coordinates, real-time positionOnly if you grant permissionShow nearby chargers, start sessionStored on device; session location kept 10 years (tax records)
Usage & diagnosticsScreen views, taps, crash logsFirebase Crashlytics, Apple App AnalyticsImprove stability & UXDiagnostics 90 days; aggregated stats 24 months
Payment & transactionsTokenised card ID, receipts, VAT No., currencyApple Pay / Google Play Billing / StripeProcess payments, comply with accounting lawFinancial data 10 years
Marketing preferencesNewsletter opt-in, consent flagsYou set in Settings or e-mailSend product newsDeleted immediately on opt-out

We do not: (a) read your contacts, photos or clipboard; (b) use third-party advertising SDKs; (c) knowingly collect data from children under 13.

Legal bases (GDPR Art. 6)

  • Contract – perform the Terms of Service.
  • Legal obligation – keep tax/transaction records.
  • Legitimate interest – secure and improve the Services.
  • Consent – for location, analytics, marketing and push notifications. You can withdraw consent in App → Settings → Privacy or by contacting us.

How we share data

We share personal data only with:

  • Processors bound by Art. 28 GDPR contracts (cloud hosting on Microsoft Azure EU, Stripe Payments Europe, Apple/Google for in-app payments, Firebase Crashlytics, SendGrid e-mail service).
  • Iskraemeco group companies (intra-group data protection agreement).
  • Public authorities when legally required.
  • Successors in corporate restructuring (we will notify you).

We never sell data or allow third-party ads.

International transfers

Where data is transferred outside the EEA we rely on:

  • Adequacy decisions (e.g. Switzerland, UK) or
  • The EU Standard Contractual Clauses with supplementary safeguards.

Your rights

You have the right to access, rectify, erase, restrict, object, port, and withdraw consent. To exercise a right:

We respond within 30 days. You may complain to the Portuguese Data Protection Authority (CNPD) or your local regulator.

Account & data deletion (App Store / Play Policy)

From 31 January 2022 (Apple) and 31 May 2024 (Google) we must let you delete your account inside the App:

App → Settings → Account → Delete My Account

  • Account and authentication data: immediate deletion.
  • Transaction records: retained 10 years, pseudonymised.
  • Push-token and location data: removed within 24 hours.

Cookies & similar tech

The Site stores your cookie choice in first-party local storage. Analytics (Google Analytics) and the third-party catalogue viewer load only after you opt in, and not before. See our Cookie Policy for the complete list and for how to withdraw consent. The Apps do not use cookies but may store secure local preferences.

Security

We apply ISO 27001-aligned controls including TLS 1.3, AES-256 encryption at rest, Argon2id password hashing, RBAC, regular penetration testing and 24/7 monitoring. No system is 100% secure but we endeavour to minimise risk.

Changes to this Policy

We may update this Policy. Material changes will be announced in-App and on the Site 14 days before they take effect. Continued use after the effective date means acceptance.

Contact or complaints

Data Protection Officer
Rua Santos Pousada, N.º 157 - 4.º, Sala 17 4000-485 Porto

General privacy enquiries: info.pt@iskraemeco.com

We aim to resolve all privacy enquiries within 30 days.