Skip to content
EVstring

Draft — to be reviewed by qualified counsel before publication. Bracketed text such as [Company legal name] marks details still to be completed.

Privacy policy

Last updated: · Status: draft

EVstring processes mainly battery and business data. The limited personal data we hold — user accounts, audit logs and, in the restricted tier, vehicle identifiers — is kept off the blockchain so that it can be corrected and erased.

1. Who we are

EVstring is a digital battery passport platform provided by [Company legal name], a company registered in [Country of incorporation] under number [Company registration number], with its registered office at [Registered address] (“EVstring”, “we”, “us”).

We act as controller (in India, data fiduciary) for personal data we process for our own purposes: running this website, managing customer accounts, securing the platform and communicating with business contacts. When our customers use EVstring to manage battery passports, we act as their processor (in India, data processor; in California, service provider) and process personal data only on their documented instructions, as set out in our Data Processing Addendum.

  • Data Protection Officer: [DPO name], [DPO email address]
  • EU representative (Art. 27 GDPR), if required: [EU representative name and address]
  • UK representative, if required: [UK representative name and address]
  • Grievance Officer (India): [Grievance Officer name], [email], [address]
  • Privacy enquiries: [privacy contact email]

2. Scope of this policy

This policy covers personal data processed through this website, the EVstring web and mobile applications, our APIs, and our business communications. It does not cover how our customers handle personal data in their own systems; for battery passport data that a customer controls, the customer’s privacy notice applies and you should contact that customer first.

EVstring is a business-to-business service. It is designed to process mainly business and product data about batteries, and only limited personal data about the people who use it.

3. Personal data we collect

CategoryExamplesSource
Account dataName, business email address, organisation, role, optional phone number, password (stored only as a salted hash)You or your organisation’s administrator
Audit and activity dataUser ID, action performed, affected battery or document, timestamp, and transaction referencesGenerated when you use the platform
Technical and security dataIP address, browser and device type, request timestamps, failed sign-in attemptsYour device and our servers
Vehicle identifiersVehicle identification number (VIN) linked to a battery, visible only in the restricted tierOur customers (we act as processor)
Documents and imagesService photos or certificates uploaded by customers, which may incidentally show people or number platesOur customers (we act as processor)
CommunicationsMessages, meeting notes and contact details when you contact us or request a demoYou

We do not collect GPS or location data from battery telemetry, special categories of personal data, or data about children. Visitors to a public battery passport page are not asked to sign in and we do not build profiles of them.

4. Purposes and legal bases

PurposeGDPR / UK GDPR legal basis
Creating and administering accounts; providing the servicePerformance of a contract (Art. 6(1)(b)), or our legitimate interest in serving our business customers (Art. 6(1)(f)) where the user is not the contracting party
Security, fraud prevention, audit trails and access loggingLegitimate interests (Art. 6(1)(f)); legal obligation where a law requires records (Art. 6(1)(c))
Responding to enquiries and managing the customer relationshipLegitimate interests (Art. 6(1)(f))
Product updates and marketing emails to business contactsConsent where required by law (Art. 6(1)(a)); otherwise legitimate interests, with an opt-out in every message
Complying with law, regulator requests and legal claimsLegal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f))

India. Where the Digital Personal Data Protection Act, 2023 applies, we process personal data on the basis of your consent, given through a clear notice, or for a legitimate use permitted by section 7 of the Act (for example, where you have voluntarily provided data for a specified purpose and have not indicated that you do not consent). You may withdraw consent at any time; withdrawal does not affect processing that took place before it.

5. Blockchain records and personal data

EVstring anchors battery records on a permissioned blockchain so they are tamper-evident. Because blockchain entries cannot be changed or deleted, we apply a strict rule: personal data is never written on-chain.

  • The ledger holds battery identifiers, lifecycle states, organisation addresses and cryptographic hashes.
  • A VIN appears on-chain only as a salted hash; the salt is held off-chain, and deleting it makes the hash unlinkable to the vehicle.
  • Restricted documents are encrypted before storage with a separate key per document. Deleting the key (“crypto-shredding”) makes every copy unreadable.
  • Names, emails, phone numbers and other account data stay in our database, where they can be corrected or erased.

6. How we share personal data

We do not sell personal data. We share it only as follows:

  • Sub-processors that host and operate the service for us (for example [Hosting provider], [Email provider]), under written contracts with data-protection terms. The current list is in Annex III of the Data Processing Addendum.
  • Other participants in a battery’s value chain (for example a recycler receiving a battery) see the business information they are entitled to see under the access tiers. This may include the name of the organisation and the role of the user who performed an action, but not account contact details unless the customer chooses to share them.
  • Authorities where we are legally required to disclose information, after checking the request is valid and, where permitted, informing the affected customer.
  • Professional advisers and, in a merger, acquisition or reorganisation, successor entities, subject to confidentiality.

7. International transfers

Our primary hosting region is [Primary hosting region]. Customers can choose the deployment region for their data where offered. If personal data is transferred across borders, we use an appropriate safeguard:

  • EU/EEA: an adequacy decision of the European Commission where available, or the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, with supplementary measures where needed.
  • United Kingdom: UK adequacy regulations, the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
  • India: transfers are permitted except to countries or territories restricted by the Central Government under section 16 of the DPDP Act, and subject to any stricter sectoral rules.
  • China: where the Personal Information Protection Law applies, transfers out of mainland China take place only through a mechanism it recognises (security assessment, standard contract or certification) or an applicable exemption.

You can request a copy of the relevant safeguards by contacting us.

8. How long we keep data

DataRetention
Account dataFor the life of the account, then deleted within [X days] unless the law requires longer
Audit logs[X years], to support regulatory record-keeping and investigations
Security logs[X days]
Enquiries and sales communications[X months] after the last interaction
Customer data processed on instructionAs instructed by the customer and set out in the Data Processing Addendum

Battery passport records that contain no personal data may be retained for as long as regulations require the passport to remain available.

9. Security

We protect personal data with technical and organisational measures appropriate to the risk, including encryption in transit (TLS), AES-256-GCM encryption of restricted documents, salted password hashing, role-based access control, rate limiting and lockout of repeated failed sign-ins, audit logging, and secrets management that keeps keys out of source code and logs.

If a personal data breach occurs we will notify the competent supervisory authority, the Data Protection Board of India and affected individuals or customers where and within the time the law requires (for example, within 72 hours of becoming aware for notifiable breaches under GDPR).

10. Your rights

EU, EEA and UK

You have the right to access, rectify and erase your personal data, to restrict or object to processing, to data portability, and to withdraw consent at any time. You may lodge a complaint with your local supervisory authority. We respond within one month, extendable by two further months for complex requests.

India (DPDP Act 2023)

As a data principal you have the right to obtain information about the processing of your personal data, to correction, completion, updating and erasure, to grievance redressal, and to nominate another person to exercise your rights in the event of death or incapacity. You can manage or withdraw consent directly with us or, once available, through a consent manager registered with the Data Protection Board of India. Please contact our Grievance Officer first; if you are not satisfied, you may complain to the Data Protection Board of India.

California (CCPA as amended by CPRA)

California residents have the right to know what personal information we collect, use and disclose; to delete and correct it; to opt out of its sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights. We do not sell personal information or share it for cross-context behavioural advertising, and we do not use sensitive personal information for purposes that would require a right to limit. You may use an authorised agent. We respond within 45 days, extendable by a further 45 days where permitted.

How to exercise your rights

Email [privacy contact email] or write to [Registered address]. We will verify your identity before acting. If your request concerns data that a customer controls, we will pass it to that customer and assist them.

11. Children

EVstring is a business service and is not directed at children. We do not knowingly process personal data of anyone under 18. If you believe we have, contact us and we will delete it.

12. Cookies and local storage

This website sets no tracking or advertising cookies. It stores only your light/dark theme preference in your browser’s local storage. The signed-in application uses one strictly necessary authentication cookie. See our Cookie policy.

13. Changes to this policy

We may update this policy. We will post the new version here with a new “last updated” date and, for material changes, notify account holders by email or in the application before the change takes effect.

14. Contact

[Company legal name], [Registered address]. Privacy: [privacy contact email]. Data Protection Officer: [DPO email address]. Grievance Officer (India): [Grievance Officer email].