Last updated: 20 July 2026
This privacy policy explains which personal data the Energy Fleet platform processes, why, and what rights you have.
Armlab BV, Sint-Hubertusstraat 67, 3730 Bilzen-Hoeselt, Belgium, company number BE 0899.277.201, develops and operates the Energy Fleet platform.
Contact for privacy questions and to exercise your rights: hello@energyfleet.be
No data protection officer has been appointed. One is not legally required for this processing.
The platform is used by organisations. Armlab BV's role differs depending on the type of data.
2.1 Armlab BV is the controller for the data needed to operate the platform itself: user accounts, authentication, roles and access rights, and the associated logging. For that data Armlab BV determines the purposes and means.
2.2 Armlab BV is a processor for a customer organisation's site, asset and energy production data. That data is processed on the instructions of that organisation, which remains the controller.
2.3 If you are a user within a customer organisation, questions about installation data should go to your own organisation. Questions about your account can be addressed to Armlab BV directly.
2.4 Where the law requires it, Armlab BV enters into a data processing agreement with the customer organisation in accordance with Article 28 GDPR.
3.1 Account data:
• Email address, used as the unique login name
• User name
• Password, stored only as a cryptographic hash, and only for local authentication
• The Microsoft Entra ID object identifier, only when signing in through Microsoft 365
• Role within the platform and the organisation the user belongs to
• Language preference and whether the account is active
3.2 Platform usage data:
• Time of last sign-in
• Time of last password change
• A token version, used to invalidate sessions on sign-out
• Notification and alert preferences
3.3 Installation data:
• Site name, address and geographic coordinates
• Asset configuration and connection settings
• Measured power, energy, self-consumption and export
Installation data concerns devices and locations rather than people. It becomes personal data where a site is traceable to an individual natural person, for example an installation on a private home. In that case the same rights and safeguards apply.
4.1 Performance of the contract (Article 6(1)(b) GDPR): creating and managing accounts, granting access, delivering monitoring and reporting.
4.2 Legitimate interest (Article 6(1)(f) GDPR): securing the platform, detecting and preventing misuse, and resolving faults. Our interest is a working and secure service; we process no more data than necessary for it.
4.3 Legal obligation (Article 6(1)(c) GDPR): where we are required by law to retain or disclose data.
We do not use your data for advertising and we do not sell it. There is no automated decision-making producing legal effects and no profiling.
5.1 Within Armlab BV, access is limited to the people who operate and support the platform.
5.2 Administrators within your own organisation can see that organisation's accounts and installation data.
5.3 We rely on the following processors:
• Microsoft — Entra ID, for Microsoft 365 sign-in
• Hetzner Online GmbH — database hosting in Falkenstein, Germany
• Brevo — SMTP relay for transactional email, using the recipient's name and email address
• GoodWe SEMS Portal, Huawei FusionSolar and Growatt — manufacturer cloud platforms, for retrieving inverter data
• Fluvius — for retrieving grid operator metering data
• Open-Meteo — weather data, receiving only a site's coordinates
5.4 All processing takes place within the European Economic Area. We do not transfer personal data to countries outside the EEA.
6.1 Account data is kept for as long as the account exists. When an account is deactivated or deleted, the associated personal data is removed within a reasonable period.
6.2 Sign-in and change records are kept for as long as needed to secure the platform.
6.3 Installation and production data is kept for the term of the agreement with the customer organisation. Historical series are retained because multi-year reporting is part of the purpose of the service. After the agreement ends the data is deleted as agreed with that organisation.
6.4 Backups are overwritten on a fixed rotation. Data may therefore remain briefly in a backup after removal from the platform.
You have the right to access your personal data, to have inaccurate data corrected, to erasure, to restriction of processing, to data portability, and to object to processing based on our legitimate interest.
Where we process data on the basis of your consent, you may withdraw that consent at any time. This does not affect processing that took place beforehand.
Requests can be sent to hello@energyfleet.be. We respond within one month. Where the request concerns installation data for which we act as processor, we will refer you to your own organisation or handle the request in consultation with it.
We take appropriate technical and organisational measures. Traffic to the platform uses an encrypted connection, passwords are stored only as hashes, credentials for manufacturer cloud platforms are stored encrypted, and access within the platform is restricted by role and organisation.
In the event of a breach posing a risk to your rights and freedoms, we notify the Belgian Data Protection Authority within 72 hours and, where the law requires, you as well.
The platform uses functional browser storage only: your session, your language choice and your display preferences. No analytics or advertising cookies are set and there are no third-party trackers.
If you are unhappy with how we handle your data, please tell us first. You also always have the right to lodge a complaint with the supervisory authority:
Gegevensbeschermingsautoriteit, Drukpersstraat 35, 1000 Brussels, Belgium — contact@apd-gba.be — www.gegevensbeschermingsautoriteit.be
We may amend this privacy policy. The date at the top shows the most recent change. Customer organisations are notified in advance of material changes.