Legal
Privacy Policy
This is a convenience translation. The German version is legally binding.
1. Controller and Data Protection Officer
Controller
United Share GmbH
Aachener Straße 1007
50858 Köln (Cologne)
Germany
Email: office@unitedshare.app
Data Protection Officer
For questions regarding data protection, you can reach our Data Protection Officer at:
Email: datenschutz@unitedshare.app
2. Purposes and Legal Bases for Data Processing
2.1 Operation of the Platform, App and Services
We process personal data to provide the UnitedShare platform, the app and the website, to set up user accounts and to enable the services offered (e.g. ShareCare rental services, rewards program, microservices).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
2.2 Registration and Security
During registration, we process data for account setup, fraud prevention and compliance with legal obligations (e.g. retention or identification requirements).
Legal basis: Art. 6(1)(b), (c) GDPR.
2.3 Rewards Program and Profiling
Participation in the rewards program is voluntary. Energy consumption data is processed to calculate points and to tokenize CO₂ savings. This constitutes profiling within the meaning of Art. 4(4) GDPR but does not have legal effects within the meaning of Art. 22 GDPR.
Legal basis: Art. 6(1)(a) GDPR (consent).
2.4 Enforcement of Terms & Conditions
We process usage data to ensure contractual use and to prevent misuse.
2.5 Use of Our Website
- Technical data: IP address, browser type, operating system, access time
- Contact forms: submitted data is stored to process your inquiry
- Tracking cookies: only with explicit consent (opt-in)
3. Categories of Personal Data
- Master data: name, address, contact details, date of birth
- Usage data: access times, pages visited, device information
- Contract data: contract content, payment information, contract history
- Technical data: IP addresses, browser type, operating system
- Special categories: only with explicit consent
4. Multi-Tenant and Role Model
The platform distinguishes between different user roles (owners, administrators, tenants, developers). Data access is restricted based on roles:
- Owners and administrators see aggregated data but not the personal details of individual tenants.
- Developers only receive access to the data required for API integrations.
Processing operations vary depending on the user role and can be viewed in the account profile.
5. API and Developer Access
When using the API or SDKs, data may be transferred to third parties. Developers are independently responsible under data protection law when they carry out their own data processing activities. UnitedShare assumes no liability in this regard.
UnitedShare ensures that only the data required for the respective integration is processed.
6. Recipients of Data
- Service providers (processors pursuant to Art. 28 GDPR), e.g. hosting, IT support, payment processing
- External advisors (lawyers, tax advisors, auditors)
- Authorities and courts, insofar as legally required
7. International Data Transfers
Master data is only transferred to third countries if an adequacy decision (Art. 45 GDPR) or appropriate safeguards such as EU Standard Contractual Clauses (Art. 46 GDPR) are in place.
For US-based providers (e.g. cloud or analytics services), we base transfers on the EU-U.S. Data Privacy Framework (DPF) or SCCs.
Note: The possibility of access by US authorities cannot be excluded.
8. Storage and Deletion
| Data Category | Retention Period |
|---|---|
| Account data | Until deletion + 3 years |
| Contract/payment data | 10 years (Section 257 German Commercial Code / HGB) |
| Energy data | Project duration + 5 years |
| API logs | 90 days |
| Blockchain data | Permanent (immutable) |
After these periods, data is deleted or anonymized.
9. Data Subject Rights
You have the following rights under the GDPR:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
- Right not to be subject to a decision based solely on automated processing (Art. 22 GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Postfach 20 04 44, 40102 Düsseldorf
To exercise your rights, please contact: datenschutz@unitedshare.app
10. Cookies and Tracking
Essential Cookies
Session management, security, language settings.
Analytics & Marketing
Usage statistics and personalized advertising (only with consent).
11. Blockchain and Token Data
In the context of tokenizing CO₂ savings, pseudonymized data may be stored on a blockchain.
Note: Subsequent deletion of this data is technically not possible; instead, anonymization/pseudonymization measures are taken so that no conclusions about natural persons can be drawn.
12. Data Security
We implement appropriate technical and organizational measures to protect personal data, including:
- Transport encryption (TLS 1.3)
- Encryption of data at rest
- Role-based access controls
- Regular penetration testing
13. Changes
We may update this privacy policy, e.g. in the event of changes in the legal framework or new features.
We will actively inform users of material changes by email or in-app notification.