Your customers' data,
treated like it's theirs.
Because it is.
WaterMe is designed and operated for the GDPR — European hosting, encryption at rest, strict tenant isolation, and data-subject rights your customers exercise themselves, inside the app. Not a policy bolted on afterwards: the architecture.
European data, on European soil.
Every consumer record — identity, readings, consumption, photos — is processed and stored inside the EU. Backups are encrypted and stay in the EU too, in a second country with a second provider.
Production
Application and database run in OVHcloud, Gravelines, France. One provider, one jurisdiction, EU law.
Encrypted backups
Off-site backups in Hetzner, Germany — a different provider and country, restore-tested on a schedule, never outside the EU.
Kept minimal by design
The app ships with no advertising or third-party analytics SDKs. Product telemetry is first-party and pseudonymous.
Four decisions we made so you don't have to worry.
Personal data is encrypted at rest.
Consumer names, emails and contact details are stored encrypted in the database itself — the plaintext columns were removed. A copy of the database without the keys yields no consumer personal data.
Every utility is isolated twice.
Tenant separation is enforced in the application and again by PostgreSQL row-level security — two independent layers, exercised by a dedicated test suite. One utility can never see another's customers.
Rights are self-service, not tickets.
Consumers export their data and delete their account from inside the app. No form, no waiting on support, no 30-day clock to manage — the right is a button.
Roles are clear from day one.
Your utility is the controller of your customers' data; WaterMe is the processor, acting on your instructions under a data-processing agreement. Console staff accounts and site visitors are the only data WaterMe controls.
Chapter III, implemented.
Security that is operated, not just written down.
Minimal, named, and covered.
The core platform never leaves the EU. Application, database, files and backups are all EU-resident, as above.
Three narrow functions involve non-EU providers: transactional email delivery, mobile push notification relay, and app crash reporting. The first two carry the minimum necessary data (an email address; a device push token) under Standard Contractual Clauses. Crash reports carry no name, email or account identifier and are stored in Sentry's EU region (Frankfurt) — the provider is US-headquartered, and Standard Contractual Clauses stand behind the residency.
Nobody buys, rents or receives consumer data for marketing. There is no data brokerage, no ad network, and no analytics resale — the subprocessor list is short enough to read in one breath, and we share it on request.
The paperwork your review needs.
Available on request as a documentation pack: our data-processing agreement, records of processing activities, retention policy, international-transfer register, breach-response procedure, and the public privacy notice. Your security questionnaire is welcome — we answer it from evidence, not adjectives.
Talk to us about data protection.
We'd rather answer a hard question before the contract than after it.
privacy@waterme.spaceThis page describes how the WaterMe platform is built and operated as of August 2026. It is provided for information and is not legal advice; compliance obligations are assessed per deployment with each utility as controller.
WaterMe · Europe-hosted water engagement platform · waterme.space