Skip to content
Solarstream
  • Integrations
  • Prices
  • Blog
  • About us
Log in Try it for free
  • Product
  • Leads & Sales
  • 3D planning
  • Quotes & customer portal
  • Project management
  • Resource planning
  • Administration
  • Field App
  • Communication hub
  • Sectors
  • For solar installers
  • For electricians
  • For building services engineers
  • For heating engineers
  • For roofers
  • Integrations
  • Prices
  • Blog
  • About us
Log in Try it for free

Privacy Policy

Version v2.13.0 Last updated August 31, 2026

Data Controller

The party responsible for data processing in connection with this website is:

Solarstream AG
c/o Switzerland Innovation Park Central
Suurstoffi 18b
6343 Rotkreuz
Switzerland

CHE-224.276.663

Email: info@solarstream.ch

For data protection inquiries, please contact: christian.bertschy@solarstream.ch


Provision of the website (log files)

Description and scope of data processing

When you access our website, i.e. even if you do not register or otherwise transmit information, information of a general nature is automatically collected. This information (server log files) includes, for example, the type of web browser, the operating system used, the domain name of your Internet service provider, your IP address, referrer URL, date and time of access and the like.

They are processed for the following purposes in particular:

  • Ensuring a smooth connection setup of the website,
  • Ensuring the smooth use of our website,
  • Ensuring and evaluating system security and stability, in particular for detecting misuse
  • for the technically error-free presentation and optimization of our website.

The data is also stored in the log files of our system. This data is not stored together with other personal data of the user. We do not use your data to draw conclusions about your person. However, we reserve the right to subsequently check the server log files if there are concrete indications of illegal use.

Recipients of the data

We use service providers for the operation and maintenance of our website who act as our processors. All service providers are contractually obliged to treat your data confidentially.


Categories of processors and other data recipients

We disclose personal data only where necessary for the purposes described in this notice. Depending on the function used, recipients fall in particular into the following categories:

  • providers of hosting, databases, authentication, file storage, synchronisation, backups and technical security;
  • providers of email, calendar, notification and communication functions;
  • providers of product analytics, error diagnostics and technical logging;
  • providers of AI-assisted analysis, document recognition, transcription and automation;
  • customer-selected integration, planning, accounting, signature or procurement platforms; and
  • authorities, grid operators and public geodata services where required for a requested function or by law.

The current register of processors and other data recipients identifies each organisation, its role, purpose, relevant data categories, processing location, applicable transfer safeguards and contractual basis. The register supplements this privacy notice and may be updated when operational details change. Material changes to the purpose, data categories, recipient category or international transfer continue to undergo legal review and are communicated separately.


International Data Transfers

Some of our processors are based in the USA or other third countries outside Switzerland. All personal data at rest is stored in Switzerland (Zurich) or the EU (Frankfurt). Infomaniak SA is based in Switzerland; no transfer safeguards are required for that processing.

Transfers of personal data are safeguarded by the following measures:

  • Signed Data Processing Agreements (DPAs)

  • EU Standard Contractual Clauses (SCCs)

  • Swiss-US Data Privacy Framework certification

  • For the separately approved Browserbase-backed building-notification automation, no routine transfer takes place until the feature has been explicitly enabled for a customer account. Before activation, we verify and document the effective processing region and the applicable safeguards. Without that review, the feature remains disabled.
    Germany has adequacy status under the Swiss Federal Act on Data Protection (FADP) — no additional safeguards are required for data processing in Frankfurt.


Contact

Description and scope of data processing

Our website contains a contact form that can be used to contact us electronically. If you use this option, the personal data entered in the input mask will be transmitted to us and stored. The processing of your personal data serves solely to process your enquiry.

At the time the message is sent, the following data is also transmitted and stored:

  • Date and time of the enquiry
  • URL from which the enquiry was made
  • IP address

Alternatively, you can contact us via the e-mail addresses provided. In this case, the user's personal data transmitted with the e-mail will be stored. This includes:

  • Date and time of the enquiry
  • URL from which the enquiry was made
  • IP address
  • as well as information about the servers involved in the e-mail communication.

You can also contact us via the telephone number provided. In this case, we collect log data that includes your telephone number and the duration of the call. We do not record calls.

Recipients of the data

Our website is maintained by service providers who act as our processors. If you send us an enquiry regarding an offer, service providers we use may receive data for these purposes if they need the data to fulfil their respective services (e.g. IT services, call centre). All service providers are contractually obliged to treat your data confidentially.


Newsletter

Description and scope of data processing

Your data is used exclusively to send you the subscribed newsletter by e-mail and, insofar as you have additionally consented to this, to evaluate how you use the newsletter and, if applicable, the content linked therein. Your name is provided so that you can be addressed personally in the newsletter and, if necessary, identified if you wish to exercise your rights as a data subject.

In order to verify that a registration is actually made by the owner of an e-mail address, we use the "double opt-in" procedure (DOI procedure) for online registration. This means that following your newsletter registration, you will receive an e-mail in which you must confirm your newsletter registration by clicking on a link.

At the time of the DOI confirmation, the following data is also stored:

  • Place, date and time of registration
  • IP address
  • E-mail address
  • If applicable, salutation, first name, surname

In addition, we evaluate your reading and usage behaviour in order to continuously improve our newsletter and adapt it to your interests and needs. To this end, we analyse whether and what you read or click on in our newsletters in order to make them even more attractive.

Recipients of the data

We use service providers for sending and the evaluations carried out who act as our processors. All service providers are contractually obliged to treat your data confidentially.


Registration

Description and scope of data processing

On our website, we offer you the option of registering by providing your personal data. The data is entered into an input mask and transmitted to us and stored. The data is not passed on to third parties. The following data is collected during the registration process:

  • First name, surname
  • E-mail address
  • Password

At the time of registration, the following data is also stored:

  • IP address
  • Date and time of registration

Your consent to the processing of this data is obtained during the registration process.

Recipients of the data

We use technical service providers for the registration process who act as our processors. All service providers are contractually obliged to treat your data confidentially.


File Storage

Users can upload files (documents, images, attachments) to the application. These files are stored in Zurich, Switzerland (Supabase Storage, AWS eu-central-2).

Access to files is controlled via row-level security policies. Files are encrypted at rest (AES-256) and in transit (TLS 1.2+). Uploaded files are deleted when the associated project or account is deleted.


Email Integration

Users can connect their Microsoft 365 or Google Workspace mailbox to the application. Access is via the Microsoft Graph API or the Gmail API respectively.

Data collected

  • Email content and attachments
  • Sender and recipient addresses
  • Subject lines and timestamps
  • Contact data (name, email address) when contact import is enabled

Purpose

The data is used to display and send emails on behalf of users within the application and to match contacts with the user's address book.

Technical implementation

  • Microsoft 365: Authentication via OAuth2 with scopes Mail.ReadWrite, Contacts.Read
  • Google Workspace: Authentication via OAuth2 with scopes gmail.modify, contacts.readonly
  • Email data remains in the user's tenant or account
  • Cached metadata (sender, subject, date) is stored in our database (see section "Categories of processors and other data recipients")

AI-Powered Email Analysis

Description

When the feature is enabled by the account owner, incoming emails are automatically analysed by an AI model provided by Infomaniak SA in Switzerland. Processing takes place exclusively in Switzerland.

Data collected and processed

  • Email text content (without attachments)
  • Sender and recipient addresses
  • Subject line
  • Project context within the application

Analysis results

  • Summary and sentiment analysis
  • Detection of action items and dates
  • Suggestions for project and contact assignment
  • Detection of potential new leads
  • Draft reply template

No automated individual decision-making

Analysis results are presented to the user as suggestions. All assignments and actions require manual confirmation by the user. No fully automated decision-making within the meaning of Art. 21 FADP takes place.

Data storage

Analysis results are stored encrypted (AES-256-GCM) in our database and automatically deleted after 90 days by default. The account owner can extend the retention period or set it to indefinite in the account settings. The original email content is not permanently stored.

Deactivation

AI analysis can be deactivated at any time in the account settings.


AI-Assisted Project and Lead Creation

Description

When a user uses the new project or lead creation flow, they may paste or upload emails, notes, PDF content, or similar business information. Solarstream sends the selected content server-side to the AI service provided by Infomaniak SA to generate suggestions for project, lead, contact, and address fields. Processing takes place exclusively in Switzerland.

Data Collected and Processed

  • pasted text, document excerpts, or user-selected email content
  • names, email addresses, phone numbers, and addresses where they appear in the provided content
  • project or lead context within the application

Purpose and User Control

The results are used only to suggest or prefill form fields. Users review and confirm suggestions before saving. No fully automated decision-making takes place.

Transfer, Training, and Retention

Transmission uses server-side TLS connections only. The Infomaniak AI service is configured so that content is processed exclusively in Switzerland, is not used to train models, and is not retained after inference. Solarstream logs only technical metadata and counters for this feature, not extracted field content. Only user-confirmed project, lead, or contact data is stored under the regular retention periods.


Calendar Synchronisation

Users can connect their Microsoft 365 or Google calendar to the application to display appointments in resource planning.

Data collected

  • Calendar events (title, time period, participants)
  • Calendar ID and synchronisation status

Technical implementation

  • Microsoft 365: Authentication via OAuth2 (Calendars.Read)
  • Google Workspace: Authentication via OAuth2 (calendar.readonly, calendar.events)
  • Calendar data is cached in our database (see section "Categories of processors and other data recipients")

Bexio Integration

Users can connect their Bexio account to import contact data into the application.

Data collected

  • Contact data: name, address, email address, phone number
  • Company name and customer number

Data flow

Data flows exclusively from Bexio to Solarstream (one-way import). No data is written back to Bexio.

Technical implementation

  • Authentication via OAuth2 with read-only scopes (contact_show, project_show)
  • Imported contacts are stored in our database (see section "Categories of processors and other data recipients")

Digital Offer and Customer Portal

Description and Scope of Data Processing

When a PV offer is delivered to you via our customer portal (/portal/[token]), you can review and update your contact and payment details there, and accept the offer electronically. Access is via a time-limited, non-guessable link (token) without a separate login.

Data Collected

  • Salutation, first name, last name, company name
  • Email address, phone number
  • Address (street, house number, postal code, city)
  • IBAN/bank details, if provided for payment processing
  • upon acceptance of the offer: IP address, browser identifier (user agent), and acceptance timestamp as evidence of the electronic signature (see "Categories of processors and other data recipients", DeepCloud AG/DeepSign)

Purpose

The data is used to review and process your offer, to update your contact details, and — in the case of acceptance — as evidentiary documentation for the legally valid electronic signature.

Technical Implementation and Retention

Portal access data is stored in our database in Zurich, Switzerland (see "Categories of processors and other data recipients"). The access token is valid for 90 days; expired tokens are cleaned up automatically. Offer and signature data belonging to archived offers is deleted automatically after 365 days. Access is protected against abuse through row-level security and rate limiting.

Building-notification automation via portal access

Description and scope of data processing

Solarstream plans a separately approved feature that can prepare or submit building notifications through official portals. This feature is disabled by default and is only enabled for a customer account after an additional approval step.

If the feature is enabled, the following data may in particular be processed:

  • project or case reference
  • name, email address and phone number of the owner or contact person
  • site address
  • technical details of the solar installation
  • uploaded forms, plans, authorisations and supporting documents
  • confirmation numbers, receipts and, where necessary, submission screenshots

Recipients and purpose

If the feature is enabled, this data may be transmitted to the responsible portal operator and to Browserbase Inc. as our processor for browser automation. The processing is used exclusively to prepare and submit a building notification and to document proof of submission.

International data transfer

The feature remains disabled until the concrete processing region and the applicable safeguards for Browserbase have been contractually documented. Without that documentation, no production use takes place.

Retention

  • upload documents for a submission: generally 30 days after successful submission
  • receipts / confirmations: generally 365 days
  • screenshots as evidence: generally 30 days and only where a reference number or receipt is not sufficient
  • technical error logs from failed runs: generally 14 days

Reach measurement

Description and scope of data processing

We use analysis tools to evaluate user behaviour. A more detailed description of the tools can be found in the "Analysis tools" chapter of this privacy policy.

The processing is based on our legitimate interest. The measurement of reach and the resulting information are suitable for adapting the web offering.

Recipients of the data

We use technical service providers for the operation and maintenance of our website who act as our processors. All service providers are contractually obliged to treat your data confidentially.


Analysis tools used

Use of PostHog

We use PostHog (PostHog Inc., USA) on our website, a powerful open-source analysis tool, to analyse user behaviour anonymously and using a session cookie for visitor recognition. Data is stored and processed on a European server in Frankfurt, Germany (EU instance). This use is carried out exclusively with anonymised and aggregated data in order to improve the user experience and analyse the performance of our content. The information collected by PostHog includes technical data such as operating system, browser and screen resolution, as well as usage patterns such as pages visited, time spent, origin page click paths and session recordings.


Data protection and data security

Application data is stored in Zurich, Switzerland (AWS eu-central-2). Analytics data is stored and processed in Frankfurt, Germany (EU). All data is encrypted at rest using AES-256 and in transit using TLS 1.2+. Access to data is controlled via row-level security policies at the database level.

For non-logged-in website visitors, PostHog does not collect personal data such as names or email addresses. For logged-in application users — provided analytics consent has been given — pseudonymised user data (user ID, email address, name) is sent to PostHog to analyse product usage and improve the user experience. This data is processed exclusively on the EU instance (Frankfurt).


Disclosure to third parties

We disclose personal data to processors, independent controllers, customer-selected recipients and legally or publicly competent bodies within the categories described above. Recipients may process personal data only for the relevant purpose and on the applicable contractual or legal basis. Current details are available in the register of processors and other data recipients.


Retention Periods

We retain your data for the following periods:

  • Server log files: 30 days
  • Contact form data: duration of business relationship + 1 year
  • Newsletter data: until unsubscribe
  • User account data: duration of contract + 30 days after account deletion
  • Uploaded files: duration of contract, deleted with the account
  • Email metadata cache: duration of contract
  • AI analysis results: 90 days after creation by default (configurable by account owner), automatic deletion
  • AI-assisted project/lead creation: The Infomaniak AI service does not retain content after inference; Solarstream stores only user-confirmed project, lead, or contact data under the regular retention periods
  • Calendar cache: duration of contract
  • Imported Bexio contacts: duration of contract, deleted with the account
  • Analytics data: as configured in PostHog (EU instance)
  • Documents for digital building-notification submissions: generally 30 days after successful submission
  • Building-notification receipts / confirmations: generally 365 days
  • Building-notification screenshots: generally 30 days and only where needed as evidence
  • Error logs from building-notification runs: generally 14 days for failed runs

Rights of the data subject

You have the following rights with regard to personal data concerning you:

  • the right to obtain information about what personal data we store about you and how we process it;
  • the right to receive a copy of your personal data in a common format;
  • the right to rectification of your personal data;
  • the right to erasure of your personal data;
  • the right to object to the processing of your personal data.

Please note that exceptions apply to these rights. To the extent permitted by law, we may refuse your request to exercise these rights.

You may revoke your consent to the processing of personal data at any time. Please note that the cancellation is only effective for the future. Processing that took place before the revocation is not affected.

For information about the personal data processed by us, please send your request for information to christian.bertschy@solarstream.ch.

Logged-in users of the Solarstream application can delete their account at any time under Settings → Security → Delete Account. Deletion anonymises content you authored and archives your team memberships immediately; automated database backups may retain copies for up to 30 days before they are permanently purged.

For data privacy requests regarding data collected by HubSpot, you can also submit a request directly via the HubSpot Data Privacy Portal.

You also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC).

Revision History

  1. Version v2.13.0 August 31, 2026

    The operational recipient inventory was separated from the versioned privacy notice. The notice now states specific recipient categories and links to a separate, continuously updated register covering roles, purposes, data categories, locations, transfer safeguards and contractual status.

  2. Version v2.12.0 August 2, 2026

    New section "Digital Offer and Customer Portal": discloses the contact and payment data collected via the customer portal (incl. IBAN) and the IP address and browser identifier captured on offer acceptance. Corrected Google Maps Platform: independent-controller relationship under the Google Controller-Controller Terms instead of a DPA; transfer safeguard now Swiss-US Data Privacy Framework with Controller SCCs as fallback.

  3. Version v2.11.0 July 29, 2026

    Correction: the Data Processing Agreement (DPA) for Kickbox, Resend, Exoscale and Vonage was stated as signed. The status now reads "being concluded".

  4. Version v2.10.0 July 10, 2026

    Fully corrected the AI-processing disclosure to Infomaniak SA (removed remaining stale Azure OpenAI references). Added new processors: Elektroform (electronic building notification), SolarProTool/Solarmarkt (material ordering) and DeepCloud AG (DeepSign, electronic signature of offers in the customer portal). The DeepSign DPA is still to be archived; the feature remains disabled by default until then.

  5. Version v2.9.0 July 6, 2026

    Clarified Google Maps Platform: on authenticated app surfaces the project map is embedded directly; loading it transfers the user's IP address to Google LLC (functional basis: contract / legitimate interest, independent of analytics-cookie consent).

  6. Version v2.8.0 June 11, 2026

    Added new processors: Google Firebase Cloud Messaging (push notifications), AEW Energie AG (grid operator), K2 Systems GmbH (design), swisstopo/GeoAdmin (geodata), ElectricSQL (synchronisation) and Bexio AG (accounting/CRM). Corrected audio transcription: Infomaniak SA (Switzerland) instead of Azure Speech.

  7. Version v2.7.0 May 29, 2026

    AI processing switched from Microsoft Azure / OpenAI Switzerland North to Infomaniak SA (Switzerland). Added new processors: Vonage Holdings Corp. (WhatsApp gateway), Google Maps Platform (address geocoding), Azure Document Intelligence (OCR), Azure Speech (speech-to-text). Cross-border transfer guarantees updated accordingly.

  8. Version v2.6.0 May 28, 2026

    Added Upstash, Unkey. Updated Slack DPA reference.

Back to top

Ready for the next step

Arrange a short product demo with our team

In 30 minutes, we’ll show you how Solarstream fits into your existing workflow – with no obligation and tailored to your business.

Book a demo › View prices ›
Solarstream

Product

  • Project management
  • Leads & Sales
  • Resource planning
  • Administration
  • Communication hub

Sectors

  • For solar installers
  • For electricians
  • For building services engineers
  • For heating engineers
  • For roofers

Company

  • Prices
  • Integrations
  • Partners
  • About us
  • Careers
  • Book a demo
  • Contact
Made in Switzerland

© 2026 Solarstream AG. All rights reserved.

Legal Notice Data Protection Terms and Conditions
Status