Privacy Policy
VINORUM METEO · As of 1.5
Please note: this is a translation for your convenience. The legally binding version is the German original; German law applies.
1. Controller and data protection officer
The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection provisions is:
- SISpro-connect GmbH & Co. KG
- Waldleite 21, 97295 Waldbrunn, Germany
- Phone: +49 9306 5342380
- E-mail: info@sispro.de
The data protection officer can be reached at the same address. For any question about data protection, or to exercise your rights, you can contact us directly at any time.
2. Definitions
This policy uses the terms of the GDPR. The most important ones in brief:
- Personal data: any information relating to an identified or identifiable person – for example name, e-mail address or IP address.
- Data subject: the person whose data is processed – here, you as the user.
- Processing: any operation performed on personal data, e.g. collecting, storing, using, transmitting or erasing.
- Controller: whoever determines the purposes and means of processing (see section 1).
- Processor: whoever processes data on our behalf, such as our hosting provider.
- Consent: your freely given, informed and unambiguous agreement to a specific processing operation.
3. General data on access (server log files)
Each time the app is accessed, our server automatically records technical data transmitted by your browser:
- the address requested, and the date and time of access
- the amount of data transferred and the status message
- browser type, version and operating system
- the IP address of the accessing device
We need this data to deliver the app, keep it stable and be able to trace misuse. We draw no conclusions about you personally and do not combine it with other data sources. The legal basis is our legitimate interest in secure, trouble-free operation (Art. 6(1)(f) GDPR).
If you use the app without an account, we limit the number of forecast requests per IP address. To do so we store a counter against the IP address for at most 10 minutes; it is then discarded automatically. This serves solely to protect against overload and misuse.
4. Cookies and storage on your device
The app sets no advertising or tracking cookies and embeds no analytics services such as Google Analytics. We use only technically necessary storage:
- Session cookie: keeps you signed in after logging in. It becomes invalid when you sign out or the session expires.
- Local storage: remembers settings such as language, light/dark mode and – in guest mode – your locations. This data stays on your device.
- Cache (IndexedDB): keeps retrieved readings briefly so that histories load faster and less data is transferred.
- Service worker: stores the app’s program files so it starts quickly and works offline.
You can remove this data yourself at any time by clearing the website data for this app in your browser, or by uninstalling the installed app.
5. Registration and account
An account requires the following details:
- First name and last name
- E-mail address (also serves as your sign-in name)
- Password – stored exclusively as a hash. We can neither read nor recover your password.
In addition, you may voluntarily provide details about your business: winery, role, business size, country and wine region, weather stations used, features of interest and viticulture software in use. These details help us tailor VINORUM to real-world practice and develop the app further. They are not required to use the app – you can omit them or change them later at any time.
The legal basis is performance of the user contract (Art. 6(1)(b) GDPR); for the voluntary details we rely on your consent (Art. 6(1)(a) GDPR). Your account data serves solely to operate the app. It is not passed on to third parties for advertising purposes.
If you register after having used the app without an account, we transfer the locations created on your device into your account so that you keep them.
6. Use without an account (guest mode)
You can also use the app without an account. In that case we process no master data about you:
- Your locations and settings stay exclusively on your device and are not transmitted to us.
- There is no synchronisation across devices.
- Only the server log files named in section 3 are processed, plus the forecast requests to the weather services named in section 9.
If you clear the website data or uninstall the app, the locations created in guest mode are gone for good – we hold no copy of them.
7. Locations of your stations
So that we can display readings and forecasts, we store for each station you create its name and geographic coordinates, as well as the order you chose.
You can set a location by search, by entering coordinates, or via your device’s location services. We access the device location only when you actively trigger the function and your browser grants permission. We do not evaluate your location continuously and create no movement profiles.
Please note: a station’s coordinates may allow conclusions about your plots. They are used solely for display in your account and are not published.
8. Credentials for third-party station systems
If you want to include stations from GEOTRACE or ADCON, you store that provider’s credentials. The following applies:
- The credentials are stored encrypted and assigned exclusively to your account – other users have no access to them.
- They never leave our server in plain text and are not shown to you again.
- They are used solely to retrieve readings from the respective provider on your behalf.
- You can change or delete them in the settings at any time.
The legal basis is performance of the user contract (Art. 6(1)(b) GDPR). The respective provider’s own privacy terms apply to their processing of your data.
9. External services and recipients
The app retrieves weather data from the following sources. For technical reasons, the IP address of your device or of our server is transmitted in the process:
- Deutscher Wetterdienst (DWD) – forecast data (MOSMIX). Retrieval goes through our server; your IP address is not transmitted to the DWD.
- Open-Meteo – weather and forecast data as well as place search. These requests are made directly from your browser; your IP address and the requested coordinates are transmitted to Open-Meteo.
- GEOTRACE and ADCON – only if you have set up such stations. Retrieval goes through our server using the credentials you stored.
The app is operated at a hosting provider within the European Union that acts for us as a processor under Art. 28 GDPR. Beyond this, your data is not passed on to third parties unless we are legally obliged to do so.
10. Push notifications
On request we inform you by push notification about important events – such as frost warnings, threshold breaches or a station fault. The following applies:
- You receive push messages only if you explicitly enable them and your device grants permission. Without that consent we send no notifications.
- When you enable them, your browser creates a push subscription. It consists of an endpoint address and cryptographic keys, which we store together with your account. A personal reference arises only through this assignment.
- Delivery technically goes through the push service of your browser or device manufacturer (e.g. Google, Apple or Mozilla). They receive the message in order to forward it to your device; this may involve a transfer to third countries – in particular the USA. We have no influence on the processing by these providers; their privacy terms apply.
- We limit the content of notifications to what is necessary (e.g. station name and reason). The push itself is sent without content – the app then fetches title and text directly from us. As a result, the push services never see the content of your messages.
- You can withdraw notifications at any time – in the app settings or via the notification settings of your browser or device. After withdrawal we delete the corresponding push subscription.
The legal basis is your consent (Art. 6(1)(a) GDPR). Withdrawal does not affect the lawfulness of processing carried out until then.
11. Disease risk indicator
For signed-in users we calculate a disease risk per station for downy mildew, powdery mildew and botrytis. This happens on our server so the app does not have to load all readings on every visit. For this we store:
- the measurement series of your stations for the last few days (temperature, humidity, precipitation, leaf wetness in 15-minute intervals). Past days no longer change and are stored once; the current day is refreshed.
- the result of the assessment per station (risk rating, confidence and the reasoning), so that the view opens immediately.
This data is assigned to your account and serves solely for display in the app. There is no evaluation across users, no disclosure and no use for other purposes. The legal basis is performance of the user contract (Art. 6(1)(b) GDPR).
If you delete a station or your account, the stored measurement series and assessments are removed with it.
The indicator is a decision aid, not spraying advice – the professional judgement remains yours.
12. App usage (statistics)
To understand how the app is actually used, we record for each account which days the app was used on. We store the date only – no time of day, no view you opened, no IP address. From that we can tell whether the app works in everyday practice and where we need to improve it.
In addition, your sign-ins tell us what kind of device you use the app on (e.g. iPhone, Android, PC). That information arises anyway when you sign in (section 4).
The legal basis is our legitimate interest in developing the app to meet real needs (Art. 6(1)(f) GDPR). We do not combine this with third-party data, we do not pass it on, and we do not build advertising profiles.
We delete the usage days automatically after 12 months. If you delete your account, they are removed with it immediately.
13. Product information and news
During registration you may voluntarily choose to receive product information and news about VINORUM by e-mail. This choice is not a condition for using the app.
The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with effect for the future – via the unsubscribe link in the respective e-mail or informally to info@sispro.de. Your e-mail address is not passed on to third parties.
14. Storage period and erasure
We process and store personal data only for as long as is necessary for the purpose, or as statutory retention periods require:
- Account and profile data and your stations: until your account is deleted.
- Credentials for third-party systems: until you remove them or delete your account.
- Server log files: usually a few days, then deleted automatically.
- Counter for misuse limiting: at most 10 minutes.
- Cached readings on your device: until the cache is renewed or cleared.
Deleting your account
You can delete your account yourself at any time: in the app under Settings → Account → “Delete account”. Your password is required to confirm. The following is deleted immediately and irreversibly:
- your account and all profile details
- all locations and their order
- your stored GEOTRACE and ADCON credentials
- your registrations for push notifications
The readings held at GEOTRACE or ADCON themselves are not affected – only what is stored in VINORUM METEO is deleted.
Without the app: you can also request deletion without having the app installed – an informal message from your registered e-mail address to info@sispro.de is enough. We will then delete your account within 30 days and confirm this to you.
15. Legal bases for processing
- Art. 6(1)(a) GDPR – consent: voluntary profile details, product information, location request, push notifications.
- Art. 6(1)(b) GDPR – performance of a contract: account, display of your stations and readings.
- Art. 6(1)(c) GDPR – legal obligation, where one applies to us.
- Art. 6(1)(f) GDPR – legitimate interest: secure and trouble-free operation, defence against misuse, further development of the app.
Our legitimate interest lies in providing the app reliably, protecting it against attacks and overload, and improving it in the interest of our users.
16. Your rights as a data subject
You have the following rights vis-à-vis us. An informal message to info@sispro.de is sufficient to exercise them.
a) Right to confirmation and access
You may at any time request confirmation as to whether we process data concerning you, and obtain free information about that data as well as a copy (Art. 15 GDPR).
b) Right to rectification
You may request the rectification of inaccurate data and the completion of incomplete data (Art. 16 GDPR). Many details you can change yourself in the settings.
c) Right to erasure
You may request the erasure of your data, provided no statutory retention reason stands in the way (Art. 17 GDPR). You can delete your account yourself in the app at any time (Settings → Account).
d) Right to restriction of processing
Under the conditions of Art. 18 GDPR you may request that we restrict processing.
e) Right to data portability
You may receive the data you provided to us in a structured, commonly used and machine-readable format, or have it transmitted to another controller (Art. 20 GDPR).
f) Right to object
You may object at any time, on grounds relating to your particular situation, to processing we base on a legitimate interest (Art. 21 GDPR).
g) Right to withdraw consent
You can withdraw consent you have given at any time with effect for the future. The lawfulness of processing carried out until then remains unaffected.
h) Right to lodge a complaint
Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence or of the alleged infringement (Art. 77 GDPR).
17. Necessity of providing data
Providing first name, last name, e-mail address and password is required for an account – without them we cannot set up access. All other details are voluntary; not providing them has no disadvantages for using the app. You can use the app entirely without providing details in guest mode (section 6).
18. Automated decision-making
Automated decision-making or profiling within the meaning of Art. 22 GDPR does not take place.
19. Data security
We have implemented numerous technical and organisational measures to protect your data as completely as possible. Transmission is encrypted via HTTPS, passwords are stored exclusively as a hash, and credentials for third-party systems are additionally stored encrypted.
Nevertheless, internet-based data transmissions can generally have security gaps, so absolute protection cannot be guaranteed. For this reason you are free to transmit personal data to us by alternative means, for example by telephone.
Provider
Information pursuant to § 5 DDG (German Digital Services Act):
- SISpro-connect GmbH & Co. KG, Waldleite 21, 97295 Waldbrunn, Germany
- Phone: +49 (0) 93 06 / 53 42 380 · Fax: +49 (0) 93 06 / 53 42 389
- E-mail: info@sispro.de · Web: www.sispro.de
- Register court: Amtsgericht Würzburg, HRA 7013
- General partner: SISpro GmbH, Waldleite 21, 97295 Waldbrunn – Amtsgericht Würzburg, HRB 11779
- Managing directors: Matthias Nürnberger, René Nürnberger
- VAT ID pursuant to § 27a UStG: DE 286 996 069
- Chamber of commerce: IHK Würzburg-Schweinfurt
- Responsible for content pursuant to § 18 (2) MStV: Matthias Nürnberger, address as above
