Skip to main content

Privacy policy

This English translation is provided for convenience. The German privacy policy remains authoritative.

1. Controller

Anesda UG (haftungsbeschränkt)
St.-Josefs-Kirchplatz 4
87700 Memmingen
Germany
Managing director: Daniel Eschenlohr
Phone: +49 8331 / 756849-0
Email: info@anesda.de

2. Data we process

Depending on the features you use, we process in particular:

  • master and contact data such as name, email address, telephone number and billing address,
  • account data such as password hash, verification status, contract acceptances and sign-in information,
  • contract, charging and billing data such as charging station, timestamps, energy amount, tariff, cost, payment method and invoices,
  • technical data such as IP address, timestamp, device, operating system, browser or app version and server logs,
  • optional location data for nearby searches and, where location permission has been granted, for QR scans,
  • QR content, reviews and charging-station images uploaded by you, as well as
  • device and push tokens if you allow notifications.

The vehicle model selected in the app for estimates and downloaded station data are currently stored only locally on your device. We do not store complete card or bank details; we retain only technical references and truncated information supplied by payment providers.

3. Purposes and legal bases

  • Account, contract, charging session, payment and support: to take steps prior to entering into a contract and to perform the user and charging contract (Article 6(1)(b) GDPR).
  • Accounting and statutory records: to comply with commercial and tax-law obligations (Article 6(1)(c) GDPR).
  • IT security, error analysis and abuse prevention: based on our legitimate interest in providing a secure and reliable service (Article 6(1)(f) GDPR).
  • Contact enquiries: depending on the content, to take pre-contractual steps (Article 6(1)(b) GDPR) or based on our legitimate interest in processing your enquiry (Article 6(1)(f) GDPR).
  • Optional location and push features: with your consent (Article 6(1)(a) GDPR). You may withdraw the permission at any time in your device settings without affecting the lawfulness of prior processing.

The account, contract and payment data marked as mandatory are required for the contract. Without them, we cannot provide the user account or paid charging sessions.

4. Website, portal and contact form

Hosting and server logs

The website, API, portal, database and email mailbox are operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Each request involves processing technically necessary connection data, particularly the IP address, timestamp, requested resource, status code, referrer, browser and operating-system information. This is necessary to deliver the service, maintain stability and defend against attacks. More information: Hetzner privacy information.

Contact form and email

When you contact us, we process your name, email address, message, technical transmission data and voluntary information to answer your enquiry. Messages are transmitted through our email infrastructure hosted by Hetzner. Data is not disclosed for advertising purposes.

Cookies and local storage

The public website does not set analytics or advertising cookies. After sign-in, the customer portal stores only the access and refresh tokens required for the signed-in session in local browser storage; technically necessary session and security cookies may also be used. This information is required for the explicitly requested sign-in and portal operation and is removed when you sign out. In the app, we use local device storage and a local database for sign-in, settings, vehicle selection and the station cache. No third-party analytics, advertising or tracking SDKs are integrated.

The website and customer portal store your selected language solely as a convenience setting in local browser storage. The setting contains no user or device identifier and is not used for analytics or advertising.

Cookie-free reach and campaign measurement

To improve the website, portal and app and to evaluate our own advertising campaigns, we count only aggregated daily events on our server. These include page views, completed registrations, configured payment methods, started subscriptions and charging sessions, as well as broad campaign keys assigned by us, such as source, medium and campaign.

The count neither sets nor reads analytics cookies and does not use local storage, fingerprinting or persistent visitor or device identifiers. We do not store IP addresses, user agents, referrers, account or session IDs, or individual raw events. We therefore cannot analyse unique visitors or personal click paths. Browser signals such as “Do Not Track” and “Global Privacy Control”, as well as the corresponding app setting, are respected and such requests are not counted. Counters aggregated by day and campaign key are deleted after 24 months.

The legal basis is our legitimate interest in designing an economical and user-friendly service (Article 6(1)(f) GDPR). You may object at any time. Processing takes place exclusively on our own infrastructure hosted by Hetzner; analytics data is not shared with advertising networks or combined with other datasets.

Purpose-bound support and security events

To handle specific account, setup, payment and charging issues, we store a time-limited event history for signed-in accounts. It contains the time, operation and result, along with broad technical details such as app or customer portal, operating system, app version and a general device hint. Failed sign-in attempts are linked to an account only if the entered email address already belongs to that account. We do not store an IP address, user agent, persistent device or fingerprinting ID, passwords, access or refresh tokens, card details, or payment or provider references for this purpose.

The events are used solely for support, error analysis and abuse prevention, are not used for advertising or profiling, and are automatically deleted after 180 days. The legal bases are contract performance (Article 6(1)(b) GDPR) and our legitimate interest in secure and reliable customer service (Article 6(1)(f) GDPR).

5. Maps, location, camera and photos

We use Google Maps Platform, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, for the map. At minimum, the IP address, device and app information, API project identifier, map requests and the visible map area are transmitted to Google. If you grant location permission and use the location feature, your position may also be processed in the map. Google may process data in third countries. Processing is based on the agreed data-protection terms, including appropriate safeguards under Articles 44 et seq. GDPR. More information: Privacy at Google Maps Platform and Google privacy policy.

Location, camera and photo library are used only after the relevant device permission is granted. The camera reads QR codes locally. QR content and, where location permission has been granted, the current position are sent to our API for recognition and abuse analysis. Photos are uploaded for station reviews only after you select them. You can revoke permissions at any time in your device settings.

6. Push notifications

If you allow push notifications, we use Firebase Cloud Messaging from Google Ireland Limited. This involves processing a device/push token, app and device information, the IP address and the message data required for delivery. Google may process data in third countries; the Firebase data-processing terms and appropriate safeguards under Articles 44 et seq. GDPR apply. More information: Privacy and security at Firebase. You can disable notifications in the device settings; the token stored by us is removed when the account is deleted.

7. Payment service providers

Depending on the selected payment method, we transmit the account, contract and transaction data required for setup, authorisation, settlement, refunds and fraud prevention to the relevant provider:

  • Stripe Payments Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, for card, SEPA, Link, Apple Pay or Google Pay. Stripe processes payment, transaction, device and fraud-prevention data, among other information, and may involve additional financial partners. Stripe privacy policy.
  • PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg, if you select PayPal. You will be redirected to PayPal to link your account. PayPal privacy policy.

Processing is necessary for contract performance (Article 6(1)(b) GDPR); statutory audit and retention obligations are based on Article 6(1)(c) GDPR. Payment providers may act as independent controllers for specific statutory or their own purposes.

8. Invoices and accounting

We use Lexware Office, provided by Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg, Germany, to create, manage and lawfully retain contacts, invoices and documents. We transmit the master, address, contract, service and billing data required for invoicing and accounting. More information: Data protection and security at Lexware Office.

9. Charging infrastructure and roaming partners

To display charging stations and tariffs and to authorise, perform and bill a charging session, we exchange the required pseudonymous token, station, tariff, session and billing data with the relevant charge-point operator or roaming partner. The specific recipient depends on the selected charging station. Processing is necessary for contract performance (Article 6(1)(b) GDPR). Public station master data may additionally be obtained from OpenChargeMap; we do not transmit user-account data to OpenChargeMap.

10. Retention and account deletion

We store personal data only for as long as required for the relevant purpose. Account data is generally retained until the account is deleted or outstanding claims have expired. Technical logs are deleted once they are no longer required for security and error analysis. Contact enquiries are deleted after final processing and expiry of applicable evidence periods.

Invoices and accounting records must generally be retained for eight years, while commercial and business correspondence must generally be retained for six years; longer periods may apply in individual cases. When an account is deleted, we remove or anonymise account, device, review and access data that is no longer required and terminate stored payment agreements. Invoice and billing data subject to statutory retention remains blocked for other purposes until the retention period expires. Backups are overwritten during regular backup cycles.

11. Recipients and international transfers

Access is limited to employees and carefully selected service providers where required for operations, support, payment, accounting or charging services. We enter into data-processing agreements under Article 28 GDPR. Transfers outside the European Economic Area may occur in particular with Google, Stripe and their subprocessors. Such transfers take place only on the basis of an adequacy decision or appropriate safeguards, especially EU standard contractual clauses; further information is available in the privacy notices linked above.

12. Your rights

Subject to the statutory requirements, you have the right of access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction (Article 18 GDPR), data portability (Article 20 GDPR) and objection to processing based on legitimate interests (Article 21 GDPR). You may withdraw consent at any time with effect for the future. To exercise these rights, send a message to info@anesda.de. You can also delete your account directly in the app or customer portal.

You may lodge a complaint with a data-protection supervisory authority. The authority responsible for our registered office is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.

13. Security and automated decisions

We protect data transfers using TLS encryption and apply appropriate technical and organisational measures. We do not make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. Payment providers may conduct their own automated fraud and risk checks; details are provided in their privacy notices.

14. Changes

We update this privacy policy when features, service providers or the legal situation change. The version published at the relevant time applies.

Last updated: 29 July 2026