Elbro AGBack to home
Current legal document

switchButler IoT (SBIOT) Privacy Policy

Version 1.0 — 17 July 2026 Document: sbiot-privacy · Effective from: 17 July 2026 · Change history: 1.0 first edition

Basis: Swiss Federal Act on Data Protection (FADP, SR 235.1) and — for users in the European Union — Regulation (EU) 2016/679 (GDPR).

1. Controller

The switchButler IoT (SBIOT) service is operated by Elbro AG, Gewerbestrasse 14, 8155 Niederhasli (ZH), Switzerland, UID CHE-107.927.973. Contact for data protection matters: info@elbro.com.

2. Principle of Data Minimisation

We process exclusively the technical and account data required for the operation of the service (art. 6 FADP — proportionality). We do not collect data for third-party marketing purposes, do not sell personal data and carry out neither profiling nor automated individual decision-making.

3. Categories of Data Processed

Account data:

  • first and last name, e-mail address, telephone number, preferred language;
  • password hash (never the password in plain text);
  • where acceptance is requested, timestamp and version of the acceptance of the Privacy Policy and the Terms of Use;
  • timestamp of e-mail verification, account status and security timestamps.

Smartphone/app data:

  • app installation ID, FCM push token;
  • platform, manufacturer, brand and model, device name;
  • operating system and version, app version and build, last access.

Installation/service data:

  • installations linked to the account and the associated permissions;
  • events, alarms, statuses and technical telemetry of compatible devices;
  • commands sent via the app or portal when using enabled functions (with technical logging of actor, action, target, time and outcome, where available, for security and traceability purposes);
  • notification history and delivery status.

Technical web portal data: security logs (IP address, user agent, timestamp) to protect the account and the service.

4. Purposes

The data are processed in order to: create and protect the account; verify the e-mail address; connect the user with the installations they are authorised for; display statuses, events, alarms and notifications; send functional push notifications via FCM; provide support and diagnostics; ensure security logging and the continuity of the service.

Overview of the processing operations:

ProcessingDataPurposeLegal basis (GDPR)RecipientsRetention
Account and sign-inAccount dataAccount creation, access, e-mail verificationContract (art. 6(1)(b))Hosting CH/DE, SMTP provideras long as the account is active
Installation monitoringInstallation/service dataDisplay of statuses, events, alarmsContract (point (b))Hosting CH/DEas per section 9
Remote commandsCommand logs (who/what/when)Execution and traceabilityContract (point (b)); legitimate interest (point (f))Hosting CH/DEas per section 9
Push notificationsFCM token, device dataDelivery of functional messagesContract (point (b))Google Firebase (FCM)as long as the app is registered
Security and misuse preventionSecurity logs (IP, user agent)Protection of account and servicelegitimate interest (point (f))Hosting CH/DEas per section 9
SupportAccount and diagnostic dataHandling of requestsContract (point (b))Hosting CH/DEfor the duration of the handling

5. Legal Bases (for Users in the EU — GDPR)

  • Performance of a contract (art. 6(1)(b) GDPR): account, functions of the service.
  • Legitimate interest (point (f)): security, misuse prevention, diagnostics.
  • Legal obligation (point (c)): retention required by law.
  • Consent (point (a)): only for any future optional functions, revocable at any time.

6. Telephone Number

The telephone number is a profile/support detail. In this version it is not verified by SMS and is not used for password recovery. Any future premium SMS services will require separate activation, consent, pricing and technical verification.

7. Technical Providers and Data Disclosure

Elbro may engage technical providers required for operation:

  • hosting/servers/database (Switzerland and/or Germany);
  • infrastructure for transactional e-mails (SMTP);
  • Google Firebase exclusively as a technical provider for push notifications (FCM). Firebase is not the authority over SBIOT accounts and does not decide on installation permissions;
  • monitoring and security tools.

The providers process data only on our instructions (processors).

8. Data Location and Disclosure Abroad

The operational servers and data are located in Switzerland and/or Germany (a country with a recognised adequate level of protection). Solely for the push notification service (FCM), push tokens may be processed by Google; the transfer is based on the applicable adequacy decisions (Swiss-U.S. / EU-U.S. Data Privacy Framework) or on standard contractual clauses.

9. Retention and Deletion

  • Account data are retained as long as the account is active.
  • Upon deletion of the account or of a device, the associated personal data are deleted from the operational systems, subject to statutory retention obligations and data required to document security-relevant operations. Residual security copies are not used for operational purposes and are deleted through the normal backup retention cycle.
  • Technical logs, the event and alarm history and telemetry are retained for as long as required for operation, diagnostics and security, and are then deleted or anonymised.

10. Data Security

We take appropriate technical and organisational measures (art. 8 FADP): encryption in transit (TLS), authentication for every access to installation data, individual access credentials per device, logging of sensitive administrative access, separation between the public network and internal interfaces.

11. Rights of Data Subjects

Every user may request: access to their own data (art. 25 FADP; art. 15 GDPR); rectification; deletion of the account and of the data; restriction of processing or objection; release/transfer of the data; withdrawal of voluntary consents. Requests to: info@elbro.com.

Complaints: Federal Data Protection and Information Commissioner (FDPIC), Switzerland; for users in the EU, the supervisory authority of their own member state.

12. Minors

The service is not directed at persons under 16 years of age without the involvement of the installation owner or of the holders of parental responsibility.

13. Changes

We update this Policy as needed. The version in force, with date and version number, is available at any time in the app and in the portal.

14. Language Versions

This Policy is published in German, French, Italian and English. In case of discrepancies, the German version shall prevail.