Privacy Policy
How Virtunet B.V. collects, uses, and protects your personal data when you use Phaeton software, the product website and the licensing portal.
Revision
This policy covers Phaeton software, the product website and the licensing portal, including optional product diagnostics from installations. Revision: 9 September 2026.
Controller
The controller responsible for processing your personal data is:
Virtunet B.V.
Dullofsakker 44
5688VD Oirschot
The Netherlands
KvK: 95773444
Email: info@virtunet.nl
Data protection contact
For privacy questions, data subject requests and complaints, contact Virtunet at:
Email: info@virtunet.nl
Data we collect
We collect and process the following personal data when you use the licensing portal:
- Email address — used for passwordless authentication (one-time sign-in codes) and to identify your portal account.
- Hashed device fingerprints — cryptographic hashes of device identifiers (machine ID, MAC address, CPU serial) used to bind a license to a specific installation. We store only the hashes, not the raw identifiers.
- Install ID — a randomly generated identifier for each Phaeton installation, used for license binding and heartbeat tracking.
- IP address — processed transiently for rate limiting, abuse prevention, and security logging. Not stored long-term in our application database.
- Session cookie — a strictly necessary HTTP-only session cookie (
phaeton_portal_session) that maintains your authenticated session. - Language preference — saved after successful sign-in and editable in your account. We record the language of each message and retain sent documents in their original form.
- Terms acceptance — acceptance dates and, for catalog purchases, commissioning and handoff, the version, purpose and related customer, installer and transaction references.
Customer accounts contain the declared household or organization name and memberships. Installer commissioning records the intended customer email, installation name, commissioning authority, handoff and access history. Provisional access covers only that handoff's licenses. After claim, the customer controls continued installer access. Operators retain reasons and history for ownership corrections, credit returns and support-assisted actions. We do not infer households from IP addresses.
Purpose and legal basis
We process your data for the following purposes under the indicated legal bases (GDPR):
- Providing the licensing service — authentication, entitlement management, license signing, and activation session handling. Legal basis: performance of a contract (Art. 6(1)(b)).
- Security and abuse prevention — rate limiting, bot protection (Cloudflare Turnstile), duplicate-use detection, and audit logging. Legal basis: legitimate interest (Art. 6(1)(f)).
- Heartbeat monitoring — periodic check-ins from licensed installations for visibility and stale-install detection. Legal basis: legitimate interest (Art. 6(1)(f)). Heartbeats never disable runtime functionality.
- Optional product diagnostics — improving compatibility, reliability, performance and ease of use through bounded reports from installations. Legal basis: consent (Art. 6(1)(a)). Sharing is off by default and can be disabled at any time in Settings → System. The diagnostics section below explains local storage, collection, retention and withdrawal.
- Purchase, ownership and terms records — delivering purchases, customer handoff and refunds under the contract (Art. 6(1)(b)); required tax/accounting records under legal obligations (Art. 6(1)(c)); and proportionate audit evidence for preventing abuse and resolving disputes under legitimate interests (Art. 6(1)(f)). Accepting a contract is not privacy or marketing consent.
Data retention
- Portal account data (email, entitlements, installation records) — retained for as long as your account is active and for a reasonable period afterward to support transfer and support workflows.
- Authentication challenges and sessions — expire after their configured validity period and cannot then authenticate. Expiry does not itself delete the database record.
- Session cookies — expire at the end of the session lifetime configured in the portal.
- Heartbeat events — retained for the duration of the license relationship for audit and support purposes.
- Financial and audit records — retained to meet applicable tax/accounting obligations, preserve the provenance of nonexpiring licenses and credits, and resolve disputes. Removing installer access or closing an account does not erase purchase history. Requests to erase or minimize personal data are reviewed against those purposes and legal obligations.
Optional usage and diagnostics
Phaeton can send small daily reports to improve compatibility, reliability, performance and ease of use. ‘Share usage and diagnostics’ is unchecked by default in first setup. Sharing starts only when you check the box and save setup, or enable sharing later and save your settings. Existing configurations without this preference remain disabled. Change the preference and preview report data under Settings → System. Charging and licensing work independently of this choice, including during network outages.
Reports contain the Phaeton version and release channel, platform and CPU architecture, broad Venus OS and charger firmware versions, charger adapter and model family, supported capabilities, counts of connection problems, missing or stale readings, recovery and observed command outcomes, polling-duration buckets, observed runtime in minutes, charging modes used, Auto control ownership, GX-link state, fixed runtime-problem categories, phase preferences, setup outcomes and update outcomes. They exclude serial numbers, device fingerprints, installation or license IDs, account details, raw logs, passwords, vehicle identifiers, charging schedules and energy readings.
We rely on your consent for optional collection, local storage and sending of reports for product improvement (GDPR Art. 6(1)(a)). You can withdraw it at any time by turning sharing off and saving the change under Settings → System. Withdrawal does not affect the lawfulness of processing based on your consent before withdrawal. Accepting license terms does not authorize these reports.
For proportionate protection of the collection endpoint against abuse, we process request metadata on the basis of our legitimate interest (GDPR Art. 6(1)(f)), including rejected requests. We do not describe the complete collection path as guaranteed anonymous: Cloudflare processes the source IP address and request metadata on receipt. The application does not join these to product totals or licensing records.
Each report receives a new random batch ID solely to recognize retries. The application retains no complete reports or combinations of characteristics; it adds totals by week and one characteristic at a time. Operators with admin or support access can view groups containing at least 20 reports. These are not unique installation counts and the threshold does not prove anonymity.
The installation holds at most one active and one pending report; data older than seven days is discarded on the next sending cycle. Turning sharing off stops collection and uploads and clears the local queue. It cannot recall data already received. The application retains batch IDs for approximately nine days, daily rotating security keys for rate limiting for approximately three days, and weekly totals for approximately thirteen months (approximately 400 days from the start of the week), while scheduled cleanup operates. The queue is stored on the installation, not in website cookies or browser storage. Setup counters exist only in the wizard’s memory while sharing is checked; unchecking clears them. They can be sent only with successfully saved setup that enables sharing. No analytics cookies are used.
Because product totals have no link to your identity, we generally cannot locate or remove your individual contribution from them. We do not create a new device profile for privacy requests. Contact info@virtunet.nl; we will explain what data we can locate and which rights apply.
Third-party processors
We use the following third-party service providers who process data on our behalf:
- Cloudflare, Inc. — hosting (Cloudflare Workers), CDN, DDoS protection, D1 database, and Turnstile bot protection. Cloudflare processes requests and IP addresses in transit. See Cloudflare Privacy Policy.
- Stripe — hosts Checkout and processes license and installer-pack payments, tax calculations and refunds. We share your invoice name, email, billing address, business VAT ID when provided and purchase reference. We retain billing revisions, prices, tax results, payment/invoice/refund identifiers, fulfillment and operator records. The portal does not store card numbers. See Stripe’s privacy policy.
- Resend, Inc. — email delivery for sign-in messages, purchase and customer-handoff contract confirmations, invoices, support requests and withdrawal/refund request acknowledgments. Resend processes your email address, message content and document attachments to deliver these service messages. See Resend Privacy Policy.
Authorized operators record support work dates, actual minutes, categories and short case references, optionally linked to a purchase. We retain the recording operator and correction history to understand licensing and payment assistance and evaluate aggregate operating costs. These records are not advertising trackers and do not monitor charger activity.
When you send a support request, we process your account email, message, selected license and device references and any attached support bundle to answer your question or resolve the reported problem. This serves your request for support or pre-contractual information under Art. 6(1)(b). A bundle can contain recent logs, charger measurements, charging settings and schedules. Known secrets and identifiers are masked on the device, but free-text logs can still contain personal data. The browser lets you review or remove the bundle before sending it through Cloudflare and Resend to our support mailbox. It is not part of optional product analytics. The portal does not retain message bodies or bundles in D1 or object storage; sent messages remain in the email delivery service and support mailbox for handling your request and necessary follow-up. Contact info@virtunet.nl for access or deletion requests.
We do not sell your data or share it with third parties for marketing purposes.
Cookies and local storage
The portal uses the following cookies:
phaeton_portal_session— a strictly necessary session cookie that keeps you signed in. It is HTTP-only, SameSite=Strict, and Secure in production. No consent is required for this cookie under the ePrivacy Directive because it is essential for the service to function.
Cloudflare Turnstile may set functional cookies for bot protection during sign-in and entitlement claim flows. These are security-functional and do not track you for advertising or analytics.
The installer commissioning form stores the nominated customer details and original request in this tab’s session storage until redemption is confirmed, so an interrupted request does not spend a second credit. Closing the tab ends this storage. The purchase form temporarily stores your billing draft and request references in this tab’s session storage so an interrupted Checkout can be retried safely. The matching draft is cleared when you view the fulfilled order; closing the tab also ends this storage. It is not used for advertising.
Optional product diagnostics use installation files and temporary wizard memory as described above. They add no website cookies or persistent browser storage; you control this separately through the sharing preference in Phaeton.
We do not use analytics cookies, advertising cookies, or third-party tracking cookies.
International transfers
Your data may be processed outside the European Economic Area by our third-party processors (Cloudflare, Stripe and Resend). These transfers are protected by appropriate safeguards including EU Standard Contractual Clauses and the EU-US Data Privacy Framework where applicable.
Your rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15) — request a copy of the data we hold about you.
- Right to rectification (Art. 16) — request correction of inaccurate data.
- Right to erasure (Art. 17) — request deletion of your data, subject to legal retention obligations.
- Right to restriction (Art. 18) — request that we limit processing of your data in certain circumstances.
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format.
- Right to object (Art. 21) — object to processing based on legitimate interest.
To exercise any of these rights, contact us at info@virtunet.nl. We respond without undue delay and within the applicable GDPR period, normally one month; we explain any permitted extension within that period.
You also have the right to lodge a complaint with the Dutch Data Protection Authority:
Autoriteit Persoonsgegevens
https://autoriteitpersoonsgegevens.nl
Children and minimum age
The licensing portal is not intended for use by persons under the age of 16. Under the Dutch implementation of the GDPR (Uitvoeringswet AVG), the minimum age for providing digital consent is 16 years.
We do not knowingly collect personal data from children under 16. If you believe that a child under 16 has provided personal data through the portal, please contact us at info@virtunet.nl and we will take steps to delete that data promptly.
Changes to this policy
We may update this privacy policy to reflect changes in our practices or legal requirements. The effective date at the top of this page will be updated accordingly. We encourage you to review this policy periodically.