1. Who we are
EVstring is a digital battery passport platform provided by [Company legal name], a company registered in [Country of incorporation] under number [Company registration number], with its registered office at [Registered address] (“EVstring”, “we”, “us”).
We act as controller (in India, data fiduciary) for personal data we process for our own purposes: running this website, managing customer accounts, securing the platform and communicating with business contacts. When our customers use EVstring to manage battery passports, we act as their processor (in India, data processor; in California, service provider) and process personal data only on their documented instructions, as set out in our Data Processing Addendum.
- Data Protection Officer: [DPO name], [DPO email address]
- EU representative (Art. 27 GDPR), if required: [EU representative name and address]
- UK representative, if required: [UK representative name and address]
- Grievance Officer (India): [Grievance Officer name], [email], [address]
- Privacy enquiries: [privacy contact email]
2. Scope of this policy
This policy covers personal data processed through this website, the EVstring web and mobile applications, our APIs, and our business communications. It does not cover how our customers handle personal data in their own systems; for battery passport data that a customer controls, the customer’s privacy notice applies and you should contact that customer first.
EVstring is a business-to-business service. It is designed to process mainly business and product data about batteries, and only limited personal data about the people who use it.
3. Personal data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, business email address, organisation, role, optional phone number, password (stored only as a salted hash) | You or your organisation’s administrator |
| Audit and activity data | User ID, action performed, affected battery or document, timestamp, and transaction references | Generated when you use the platform |
| Technical and security data | IP address, browser and device type, request timestamps, failed sign-in attempts | Your device and our servers |
| Vehicle identifiers | Vehicle identification number (VIN) linked to a battery, visible only in the restricted tier | Our customers (we act as processor) |
| Documents and images | Service photos or certificates uploaded by customers, which may incidentally show people or number plates | Our customers (we act as processor) |
| Communications | Messages, meeting notes and contact details when you contact us or request a demo | You |
We do not collect GPS or location data from battery telemetry, special categories of personal data, or data about children. Visitors to a public battery passport page are not asked to sign in and we do not build profiles of them.
4. Purposes and legal bases
| Purpose | GDPR / UK GDPR legal basis |
|---|---|
| Creating and administering accounts; providing the service | Performance of a contract (Art. 6(1)(b)), or our legitimate interest in serving our business customers (Art. 6(1)(f)) where the user is not the contracting party |
| Security, fraud prevention, audit trails and access logging | Legitimate interests (Art. 6(1)(f)); legal obligation where a law requires records (Art. 6(1)(c)) |
| Responding to enquiries and managing the customer relationship | Legitimate interests (Art. 6(1)(f)) |
| Product updates and marketing emails to business contacts | Consent where required by law (Art. 6(1)(a)); otherwise legitimate interests, with an opt-out in every message |
| Complying with law, regulator requests and legal claims | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
India. Where the Digital Personal Data Protection Act, 2023 applies, we process personal data on the basis of your consent, given through a clear notice, or for a legitimate use permitted by section 7 of the Act (for example, where you have voluntarily provided data for a specified purpose and have not indicated that you do not consent). You may withdraw consent at any time; withdrawal does not affect processing that took place before it.
5. Blockchain records and personal data
EVstring anchors battery records on a permissioned blockchain so they are tamper-evident. Because blockchain entries cannot be changed or deleted, we apply a strict rule: personal data is never written on-chain.
- The ledger holds battery identifiers, lifecycle states, organisation addresses and cryptographic hashes.
- A VIN appears on-chain only as a salted hash; the salt is held off-chain, and deleting it makes the hash unlinkable to the vehicle.
- Restricted documents are encrypted before storage with a separate key per document. Deleting the key (“crypto-shredding”) makes every copy unreadable.
- Names, emails, phone numbers and other account data stay in our database, where they can be corrected or erased.
6. How we share personal data
We do not sell personal data. We share it only as follows:
- Sub-processors that host and operate the service for us (for example [Hosting provider], [Email provider]), under written contracts with data-protection terms. The current list is in Annex III of the Data Processing Addendum.
- Other participants in a battery’s value chain (for example a recycler receiving a battery) see the business information they are entitled to see under the access tiers. This may include the name of the organisation and the role of the user who performed an action, but not account contact details unless the customer chooses to share them.
- Authorities where we are legally required to disclose information, after checking the request is valid and, where permitted, informing the affected customer.
- Professional advisers and, in a merger, acquisition or reorganisation, successor entities, subject to confidentiality.
7. International transfers
Our primary hosting region is [Primary hosting region]. Customers can choose the deployment region for their data where offered. If personal data is transferred across borders, we use an appropriate safeguard:
- EU/EEA: an adequacy decision of the European Commission where available, or the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, with supplementary measures where needed.
- United Kingdom: UK adequacy regulations, the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
- India: transfers are permitted except to countries or territories restricted by the Central Government under section 16 of the DPDP Act, and subject to any stricter sectoral rules.
- China: where the Personal Information Protection Law applies, transfers out of mainland China take place only through a mechanism it recognises (security assessment, standard contract or certification) or an applicable exemption.
You can request a copy of the relevant safeguards by contacting us.
8. How long we keep data
| Data | Retention |
|---|---|
| Account data | For the life of the account, then deleted within [X days] unless the law requires longer |
| Audit logs | [X years], to support regulatory record-keeping and investigations |
| Security logs | [X days] |
| Enquiries and sales communications | [X months] after the last interaction |
| Customer data processed on instruction | As instructed by the customer and set out in the Data Processing Addendum |
Battery passport records that contain no personal data may be retained for as long as regulations require the passport to remain available.
9. Security
We protect personal data with technical and organisational measures appropriate to the risk, including encryption in transit (TLS), AES-256-GCM encryption of restricted documents, salted password hashing, role-based access control, rate limiting and lockout of repeated failed sign-ins, audit logging, and secrets management that keeps keys out of source code and logs.
If a personal data breach occurs we will notify the competent supervisory authority, the Data Protection Board of India and affected individuals or customers where and within the time the law requires (for example, within 72 hours of becoming aware for notifiable breaches under GDPR).
10. Your rights
EU, EEA and UK
You have the right to access, rectify and erase your personal data, to restrict or object to processing, to data portability, and to withdraw consent at any time. You may lodge a complaint with your local supervisory authority. We respond within one month, extendable by two further months for complex requests.
India (DPDP Act 2023)
As a data principal you have the right to obtain information about the processing of your personal data, to correction, completion, updating and erasure, to grievance redressal, and to nominate another person to exercise your rights in the event of death or incapacity. You can manage or withdraw consent directly with us or, once available, through a consent manager registered with the Data Protection Board of India. Please contact our Grievance Officer first; if you are not satisfied, you may complain to the Data Protection Board of India.
California (CCPA as amended by CPRA)
California residents have the right to know what personal information we collect, use and disclose; to delete and correct it; to opt out of its sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights. We do not sell personal information or share it for cross-context behavioural advertising, and we do not use sensitive personal information for purposes that would require a right to limit. You may use an authorised agent. We respond within 45 days, extendable by a further 45 days where permitted.
How to exercise your rights
Email [privacy contact email] or write to [Registered address]. We will verify your identity before acting. If your request concerns data that a customer controls, we will pass it to that customer and assist them.
11. Children
EVstring is a business service and is not directed at children. We do not knowingly process personal data of anyone under 18. If you believe we have, contact us and we will delete it.
12. Cookies and local storage
This website sets no tracking or advertising cookies. It stores only your light/dark theme preference in your browser’s local storage. The signed-in application uses one strictly necessary authentication cookie. See our Cookie policy.
13. Changes to this policy
We may update this policy. We will post the new version here with a new “last updated” date and, for material changes, notify account holders by email or in the application before the change takes effect.
14. Contact
[Company legal name], [Registered address]. Privacy: [privacy contact email]. Data Protection Officer: [DPO email address]. Grievance Officer (India): [Grievance Officer email].