Skip to content
GDPR · Data protection

Your customers' data,
treated like it's theirs.
Because it is.

WaterMe is designed and operated for the GDPR — European hosting, encryption at rest, strict tenant isolation, and data-subject rights your customers exercise themselves, inside the app. Not a policy bolted on afterwards: the architecture.

Where the data lives

European data, on European soil.

Every consumer record — identity, readings, consumption, photos — is processed and stored inside the EU. Backups are encrypted and stay in the EU too, in a second country with a second provider.

FRANCE · EU

Production

Application and database run in OVHcloud, Gravelines, France. One provider, one jurisdiction, EU law.

GERMANY · EU

Encrypted backups

Off-site backups in Hetzner, Germany — a different provider and country, restore-tested on a schedule, never outside the EU.

EU BY DEFAULT

Kept minimal by design

The app ships with no advertising or third-party analytics SDKs. Product telemetry is first-party and pseudonymous.

Privacy by architecture

Four decisions we made so you don't have to worry.

01

Personal data is encrypted at rest.

Consumer names, emails and contact details are stored encrypted in the database itself — the plaintext columns were removed. A copy of the database without the keys yields no consumer personal data.

02

Every utility is isolated twice.

Tenant separation is enforced in the application and again by PostgreSQL row-level security — two independent layers, exercised by a dedicated test suite. One utility can never see another's customers.

03

Rights are self-service, not tickets.

Consumers export their data and delete their account from inside the app. No form, no waiting on support, no 30-day clock to manage — the right is a button.

04

Roles are clear from day one.

Your utility is the controller of your customers' data; WaterMe is the processor, acting on your instructions under a data-processing agreement. Console staff accounts and site visitors are the only data WaterMe controls.

Data-subject rights

Chapter III, implemented.

Access & portabilityOne-tap JSON export of the consumer's own data, from the app — Articles 15 and 20.
ErasureAccount deletion in-app. Meter readings that form the utility's regulated records remain with the utility, exactly as Article 17(3) provides — and our privacy notice says so plainly rather than hiding it.
RectificationConsumers edit their own details; utilities correct the customer of record.
Objection & restrictionPush notifications run on consent and switch off at OS level; processing beyond the service contract is not performed.
TransparencyA public privacy notice in plain language — what is processed, why, on which legal basis, kept how long.
Article 32 · Security of processing

Security that is operated, not just written down.

Multi-factor authentication enforced for platform administrators; minimum 12-character passwords for admin accounts.
Every administrative change is audited — create, update and delete actions carry an audit trail with the acting identity.
Encrypted, off-site, restore-tested backups — the restore drill is exercised, not assumed.
A written breach-response runbook covering assessment, containment and the 72-hour notification duty.
Sessions can be revoked — sign-out invalidates tokens server-side; a compromised credential family is cut off, not waited out.
TLS everywhere, secrets filtered from logs, and independent monitoring that pages when scheduled jobs fail to run.
Chapter V · International transfers

Minimal, named, and covered.

The core platform never leaves the EU. Application, database, files and backups are all EU-resident, as above.

Three narrow functions involve non-EU providers: transactional email delivery, mobile push notification relay, and app crash reporting. The first two carry the minimum necessary data (an email address; a device push token) under Standard Contractual Clauses. Crash reports carry no name, email or account identifier and are stored in Sentry's EU region (Frankfurt) — the provider is US-headquartered, and Standard Contractual Clauses stand behind the residency.

Nobody buys, rents or receives consumer data for marketing. There is no data brokerage, no ad network, and no analytics resale — the subprocessor list is short enough to read in one breath, and we share it on request.

For your DPO

The paperwork your review needs.

Available on request as a documentation pack: our data-processing agreement, records of processing activities, retention policy, international-transfer register, breach-response procedure, and the public privacy notice. Your security questionnaire is welcome — we answer it from evidence, not adjectives.

Talk to us about data protection.

We'd rather answer a hard question before the contract than after it.

privacy@waterme.space

This page describes how the WaterMe platform is built and operated as of August 2026. It is provided for information and is not legal advice; compliance obligations are assessed per deployment with each utility as controller.

WaterMe · Europe-hosted water engagement platform · waterme.space