Privacy Policy
Last updated: 8 July 2026 · Beta version
CyberEMS is a smart home Energy Management System (EMS), currently in private beta. We care about your privacy and collect as little data as possible. This policy explains, in plain language, what data we collect, why, and what rights you have under the GDPR.
Beta note: CyberEMS is operated by CyberEMS. Full company legal details (legal form, chamber of commerce number, registered address) will be added at general availability. Questions? Email [email protected].
What data do we collect?
- Account data. Your email address, managed through our sign-in service (Keycloak). We use this to create your account, let you sign in, and communicate with you about the beta.
- Household energy data. Through cloud integrations you connect yourself, we retrieve metering and device data such as consumption and feed-in, solar production, battery state of charge (SoC), electric-vehicle charging data, heat-pump status, and dynamic energy prices. Exactly which data arrives depends on the integrations you enable.
- Technical usage data. Limited logs (for example error messages and timestamps) to keep the service reliable and secure.
We deliberately do not collect unnecessary personal data. We never sell your data.
What do we use this data for?
- Creating and managing your account and letting you sign in securely.
- Showing and analyzing your energy flows, and computing recommendations and optimizations (for example smart charging and maximizing solar self-consumption).
- Operating, improving, and securing the service during the beta.
- Communicating with you about the beta and important changes.
The legal bases are the performance of our agreement with you (delivering the beta) and our legitimate interest in operating and securing the service.
Third-party integrations
CyberEMS works exclusively through cloud integrations that you connect yourself. When you enable an integration, we exchange data with that provider on your behalf. Depending on your choices, this may include: Homey, HomeWizard, Tesla, SolarEdge, Enphase, Zonneplan, Tibber and similar services.
- Each provider's own privacy policy applies; we do not control how they process your data.
- Access tokens and API keys are stored encrypted.
- You can disconnect an integration at any time; after that we no longer retrieve new data through it.
How long do we keep data?
We keep data no longer than necessary. During the beta we retain your energy data to show history, trends, and savings. If you delete your account or request deletion, we erase your personal data within a reasonable period, except where we are legally required to retain something.
Your rights (GDPR)
You have the right to:
- access your data;
- correct inaccurate data;
- erase your data ("right to be forgotten");
- restrict or object to processing;
- data portability;
- lodge a complaint with your data protection authority (in the Netherlands, the Autoriteit Persoonsgegevens).
Want to exercise one of these rights? Email [email protected] and we'll help you.
Security
We apply reasonable technical and organizational measures, including encryption of connected tokens and strict per-household data separation. No system is 100% secure, and this is beta software (see our terms).
Contact
Questions about privacy or your data? Reach us at [email protected].