EYKON Global Privacy Policy
Last Update: August 2026
1 Introduction
EYKON AG and its subsidiaries and affiliates worldwide (collectively, the “Company,” “we,” “us,” or “our”) may act as Data Controller, Data Processor, or in an equivalent capacity under applicable local data protection laws, depending on the nature of the processing activity and the Company’s relationship with you.
The Company collects and processes Personal Data in its day-to-day operations. This Global Privacy Policy (“Policy”) describes the Company’s practices and the relevant data privacy principles regarding the protection of Personal Data during the processing of Personal Data of its customers, contractors, website visitors, job applicants and other business partners (“Data Subjects” or similar under Applicable Law). The Company’s core activity is the business-to-business supply of smart metering equipment, metering data and related services; the Personal Data addressed in this Policy accordingly relates principally to the employees, representatives and contact persons of the Company’s business customers and partners, rather than to individual consumers.
For the purposes of the scope of this Policy, Company shall mean EYKON AG and its affiliates (“Affiliates”), all considered as part of the group companies.
2 Definitions
“Applicable Law” refers to the relevant data protection legislation applicable in the jurisdiction of the relevant Data Subject or the jurisdiction in which the Processing activity takes place.
“Data Controller” is the natural or legal person, public authority, agency or any other body which alone or jointly with others determines the purposes and means of the processing of personal data. This definition corresponds to the “Controller” under the EU GDPR (Article 4(7)) and the German Federal Data Protection Act (Bundesdatenschutzgesetz, “BDSG”). Under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”), this role is performed by the “Data Fiduciary.”
“Data Processor” is a natural or legal person, public authority, agency or any other body that processes personal data on behalf of the controller. This definition corresponds to the “Processor” under the EU GDPR (Article 4(8)).
“Data Subject” is the identified or identifiable natural person to whom Personal Data relates. Under the India DPDP Act, this role is referred to as the “Data Principal”.
“Personal Data” means any information relating to an identified or identifiable natural person (“Data Subject”) or the equivalent concept under Applicable Law.
“Processing” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
“Supervisory Authority” means an independent public authority responsible for monitoring the application of data protection law, including: (i) a data protection authority within the EU/EEA, including, for Germany, the competent Land (state) data protection authority or, in respect of federal bodies, the Federal Commissioner for Data Protection and Freedom of Information (Bundesbeauftragte für den Datenschutz und die Informationsfreiheit, “BfDI”); (ii) the UK Information Commissioner’s Office (ICO); (iii) the Swiss Federal Data Protection and Information Commissioner (FDPIC); and (iv) the Data Protection Board of India (DPBI).
“Grievance Officer” means the individual designated by the Company under the India DPDP Act and its implementing rules as the point of contact for Data Principals to raise complaints regarding the Processing of their Personal Data.
3 Scope and Applicable Law
The Company is committed to complying with Applicable Law and to processing Personal Data in accordance with applicable principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, security and accountability, where and to the extent required by Applicable Law.
The Company operates internationally and applies this Policy as a common framework across its Affiliates, with a particular focus on compliance with EU data protection law, supplemented by jurisdiction-specific requirements where necessary.
Applicable legal frameworks may include, where relevant: Regulation (EU) 2016/679 (EU General Data Protection Regulation or “EU GDPR”); the UK GDPR and the UK Data Protection Act 2018; the Swiss Federal Act on Data Protection (“FADP”); Germany’s Federal Data Protection Act (Bundesdatenschutzgesetz, “BDSG”); France’s Data Protection Act No. 78-17 of 6 January 1978, as amended (the Loi Informatique et Libertés); India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and applicable rules; and other applicable data protection and privacy legislation in the jurisdictions in which the Company operates.
Where the requirements of Applicable Law differ from this Policy, the requirements of the applicable law will prevail.
4 Collecting & Processing Personal Data
4.1 Categories of Personal Data
The Company may process the following categories of Personal Data, as applicable to the relevant business relationship:
- Identity data: last name, first name, job title and employer or business affiliation;
- Contact data: postal address, email address, telephone number and other contact details;
- Product data: product model, serial number, usage data and related technical information;
- Service data: information relating to services provided, including metering data;
- Metering-related data: electricity consumption and other meter-generated data;
- Customer relationship and invoicing data;
- Business partner feedback and correspondence;
- Recruitment and employment-related data: information collected during recruitment and employment processes, including identification and contact details, education and professional qualifications, employment history, CVs, interview records, references, compensation expectations, work authorization and, where permitted by Applicable Law and necessary for the position, background screening information;
4.2 Sources of Personal Data
We collect Personal Data from the following sources:
- Directly from you, when you provide information to us (for example, when entering into a contract, submitting an inquiry, applying for a position, or registering on our platforms);
- Automatically, through your use of our websites, digital platforms and connected products (for example, through cookies, pixels, metering devices and usage logs);
- From third parties, including business partners, recruitment agencies, professional references, publicly available sources, government databases, and credit or identity verification agencies, where permitted by Applicable Law;
4.3 Purposes of Processing and Legal Bases
We process Personal Data only where a valid legal basis or lawful ground exists under Applicable Law. The specific legal basis applicable to each processing activity depends on the jurisdiction and the nature of the data.
When conducting marketing activities to potential customers and business contacts, we rely on consent.
We rely on the legal basis of performance of a contract for the following processing:
- Contract management
- After-sales services and customer support
- Claims management
- Invoicing and billing management
- Recruitment and employment
In addition, we process Personal Data on the basis of our legitimate interests, where permitted by Applicable Law, provided that such interests are not overridden by your interests, rights, or freedoms. Where we rely on legitimate interests, we have conducted a balancing assessment where required.
This Processing includes:
- Marketing purposes (for example, sending newsletters or updates) for existing customers to propose related products and services to our customers
- Conducting statistical/usage analysis on our product usage and performance to improve our products
- Information security and preventing fraudulent activities to manage our infrastructure
- Profiling to better manage customer relationships, not subject to automated decision-making
- Video-surveillance on the Company’s premises for security purposes
- Video call recordings for business meetings to facilitate documentation and meeting minutes
The Company may also process Personal Data on the basis of fulfilling legal obligations for due diligence know-your-customer requirements.
4.4 Sensitive Personal Information
The Company does not seek to collect Sensitive Personal Information as part of its standard commercial operations. For the purposes of this Policy, “Sensitive Personal Information” means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, sex life or sexual orientation, or data relating to offences or criminal convictions, as defined under Applicable Law. Where Sensitive Personal Information is collected in specific contexts (for example, in the context of employment, where required by Applicable Law, or where voluntarily provided by the Data Subject), the Company will:
- Process such information only to the extent permitted by Applicable Law;
- Implement appropriate additional safeguards to protect such information; and
- Retain such information only for as long as necessary and in accordance with applicable legal requirements.
4.5 Limitations of Use
The Company processes Personal Data only for the purposes for which it was collected, or for compatible purposes as permitted by Applicable Law. Personal Data will not be processed in a manner that is incompatible with those purposes without the Data Subject’s prior consent, except where required by law.
4.6 Retention Period of Personal Data
We retain your Personal Data only for as long as necessary to fulfill the purposes described in this Policy or to comply with applicable legal requirements. Accordingly, the retention period for your Personal Data varies depending on the specific purpose for which it is processed.
Personal Data will be deleted as soon as the purpose of the Processing of Personal Data has been achieved as defined by our data retention schedules, but may be retained longer, if necessary, in order to comply with legal obligations or other Applicable Law or, if necessary, to protect or exercise the Company’s rights.
In the context of a job application, your CV and the information you provide during the recruitment process will be kept for up to 2 years after your last contact with the Company, unless you object to such retention, or unless your consent permits a longer retention period.
The retention period may vary depending on the country where the Data Subject resides and on the Applicable Law.
4.7 Disclosure of Personal Data
Personal Data may be shared with other Company Affiliates, government agencies and third parties to meet the Company’s contractual obligations, for legitimate business reasons or as otherwise allowed or required by Applicable Law. Third parties who may process your Personal Data include our service providers acting as Data Processors for the Company, providing the following services: data hosting, business productivity applications, customer service support software and customer relationship management software.
Government agencies may access Personal Data as a result of lawful requests, including to meet national security or law enforcement requirements.
We implement contracts with our third-party service providers to ensure that Personal Data is processed in compliance with this Policy and any other appropriate confidentiality and security measures as required by Applicable Law.
4.8 Cross-border Transfers of Personal Data
The use of third parties, and internal business processes, may require the transfer of Personal Data across country borders. Where Personal Data is transferred to a third party or to a country not recognized as providing an adequate level of protection under Applicable Law, the Company relies on one or more of the following transfer mechanisms, as appropriate:
- Standard Contractual Clauses (SCCs) as approved by the relevant Supervisory Authority or according to Applicable Law;
- An adequacy decision by the relevant Supervisory Authority in respect of the destination country;
- Other supplementary or alternative transfer mechanisms permitted under Applicable Law, including where required, a Transfer Impact Assessment (TIA).
The Company will also comply with applicable jurisdiction-specific requirements.
4.9 Security Measures
The Company implements appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. These measures include, among others, access controls, password protection, encryption, regular security assessments, and staff training on data protection obligations.
In the event of a data breach incident, the Company has procedures in place to:
- Investigate and assess the breach to determine its scope and consequences for the rights and freedoms of affected Data Subjects;
- Notify the competent Supervisory Authority and, where required, the affected Data Subjects, within the timeframes prescribed by Applicable Law;
- Implement necessary measures to remediate and mitigate the data breach;
- Maintain records of all breaches in accordance with applicable legal requirements.
The specific notification obligations applicable to a breach, and the applicable timeframes, will vary depending on Applicable Law and the circumstances of the breach.
4.10 Artificial Intelligence
The Company may use artificial intelligence (“AI”) technologies, including machine learning and generative AI tools, to support its business operations, improve its products and services, enhance customer support, analyze information, increase operational efficiency and assist employees in performing their duties.
Where AI technologies are used to process Personal Data, such Processing will be carried out in accordance with Applicable Law and the principles set out in this Policy. The Company implements appropriate technical and organizational measures designed to ensure that Personal Data processed through AI systems remains protected and is used only for authorized purposes.
The Company does not use AI systems to make decisions based solely on automated Processing that produces legal effects concerning individuals or significantly affects them.
Where the Company makes available AI-enabled functionalities within its products or services, or uses third-party AI service providers, Personal Data will be processed only to the extent necessary for the relevant purpose and subject to appropriate contractual, technical and organizational safeguards.
4.11 Cookies and Tracking Technologies
Our websites and digital platforms use cookies to collect information (e.g., the dates and times you access the website, the browsers, operating systems and devices you use to access the website, the website pages you access, and the referring and exit website pages) to operate and improve our services, analyze usage, and, where applicable and with your consent, deliver relevant content and advertising.
A “cookie” is a small text file placed on your device when you visit a website. We use the following categories of cookies:
- Strictly necessary cookies: required for the operation of our websites and cannot be disabled without affecting functionality;
- Analytical/performance cookies: allow us to recognize and count visitors and to understand how visitors move around our websites;
- Functionality cookies: used to recognize returning visitors and personalize content;
- Targeting/advertising cookies: used to deliver more relevant advertising and to measure the effectiveness of advertising campaigns.
Where required by Applicable Law, we will obtain your consent before placing non-essential cookies. You may withdraw or manage your consent at any time through our cookie preference center, accessible via the cookie banner on our websites. Please note that restricting certain cookies may affect the functionality of our websites.
Email communications sent to you may contain a tracking pixel (or similar tracker) allowing us to measure whether the email has been opened and analyze your interactions, in order to personalize our communications and measure campaign performance. This tracking is based on your consent, which you may withdraw at any time via the link provided in the email you receive.
5 Privacy Rights
Depending on your location and Applicable Law, you may have the following rights related to your Personal Data:
- Right of access
- Right to rectification
- Right to erasure
- Right to object and withdraw consent
- Right to restriction of processing
- Right to Personal Data portability
- Right to object to automated individual decision-making
Please see Section 7 to exercise any of these rights.
The exercise of such rights is not absolute and is subject to the limitations provided by Applicable Law.
You also have the right to lodge a complaint with the relevant Supervisory Authority in your jurisdiction if you are not satisfied by the Company’s response.
To exercise the above rights, the Data Subject may contact the Company as described in the section “7| How to contact us.”
6 Updates to this Policy
The Company may need to update this Policy in order to comply with new regulatory requirements. An updated version of this Policy will be made available via an appropriate channel and will apply only to data collected and processed subsequent to its effective date. The effective date of the current version is shown at the top of this Policy.
7 How to contact us and Complaint Handling
For any concerns about this Policy or in order to exercise your privacy rights in accordance with Applicable Law, please submit a request via our dedicated portal.
You may also contact our Data Protection Officer or, for Data Subjects in India, our Grievance Officer, at: Privacy@eykon-solutions.com
You may also contact us by postal mail at the following address:
EYKON AG Alte Steinhauserstrasse 18 – 6330 Cham – Switzerland.
We will endeavor to respond to all privacy-related requests within 30 days. In complex cases, or where permitted by Applicable Law, this period may be extended. We will inform you of any such extension and the reasons for it.