GDPR Compliance
Last updated: September 2026
This page describes how we handle personal data that you, as a workshop or tuning business, entrust to us when you use our portal. It is aimed at business customers who need to document their own compliance before working with us.
Information on data we process about you as our contractual partner is set out in our Privacy Policy. The contractual framework is set out in our General Terms and Conditions for Business Customers, in particular section 5.7.
1. Our role
1.1 We act in two distinct capacities.
1.2 As controller for the data of our own contractual partners: your company details, contact details, account data, orders and invoicing data.
1.3 As processor on your behalf for personal data relating to your own end customers that reaches us through the portal — in particular vehicle identification numbers, registration numbers and mileage contained in uploaded files or order details. We process this data solely on your documented instructions and not for our own purposes.
1.4 You remain the controller for that data. You are responsible for having a legal basis to transfer it to us.
2. What we process on your behalf
2.1 Original control unit files uploaded by you.
2.2 Vehicle data submitted with an order: manufacturer, model, year, engine, control unit type, software version, existing modifications.
2.3 Optionally, a vehicle identification number, where you choose to provide one. This is not required for our services.
2.4 Any information you add to an order or to a support ticket.
3. Technical and organisational measures
3.1 Transport encryption. All traffic between your browser and the portal is encrypted using TLS. The portal is served exclusively over HTTPS.
3.2 Encryption at rest. Uploaded and delivered files are stored encrypted at file level on the server.
3.3 Passwords are stored only as cryptographic hashes and are not visible to us in plain text.
3.4 Access control. The portal uses three roles. Administrator has full access to the system and to customer files; this role is currently held by the owner of the business only. Tuner is intended for staff working on files; no such accounts are currently in use. Client gives access only to that customer's own account, orders and files.
3.5 Server logs are retained for a limited period and then deleted automatically.
3.6 Backups of the database are created automatically every day and additionally before every portal update. Backups that are no longer required are reviewed and deleted at regular intervals once more recent backups are available.
3.7 Separation of purposes. Data transmitted to our accounting system is limited to what is required for invoicing. Vehicle data, vehicle identification numbers and uploaded files are not transferred to it.
3.8 Anonymisation. Where we use technical data from completed orders to improve our database, anonymisation takes place before the data enters that database. Vehicle identification numbers are never part of it; where a VIN is supplied, it is used exclusively to generate a vehicle-bound copy protection for the file concerned.
4. Subprocessors
4.1 We use the following subprocessors:
Hosting
ETH-Services, owner Lennart Seitz, Finkenweg 4, 26160 Bad Zwischenahn, Germany
VAT ID: DE362373507
Server location: Frankfurt am Main, Germany
Purpose: operation of the server on which the portal runs.
Data processing agreement: concluded.
Accounting
Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg, Germany
Purpose: invoicing and bookkeeping. Only billing data is transferred: name, address, company name where applicable, VAT identification number, amounts, service type and service date.
Data processing agreement: concluded.
Payment processing
Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, Ireland
PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg
Purpose: processing of payments. We never receive or store complete card details.
4.2 We do not engage any further subprocessors with access to data processed on your behalf.
4.3 We will inform you in text form before adding or replacing a subprocessor, and you may object.
5. Location of processing
5.1 The portal and all uploaded files are hosted exclusively in Germany.
5.2 Transfers outside the European Union occur only in connection with payment processing, and only to the extent required for that purpose. The providers named in section 4 are established in the EU.
6. Retention and deletion
6.1 Account data is retained for as long as the account exists.
6.2 Orders and the associated files currently remain available in the portal without an automatic time limit. We are introducing automated deletion with the following periods: six years for general business records and ten years for records subject to tax retention obligations under German law.
6.3 Backups are reviewed at regular intervals and deleted once they are no longer required, at the latest when more recent backups covering the same data are available.
6.4 You can request deletion of individual orders and files at any time. Statutory retention obligations remain unaffected.
7. Data subject rights
7.1 Where your end customer exercises rights in relation to data we process on your behalf, the request should be addressed to you as the controller.
7.2 We will support you in responding, in particular by providing information about the data concerned, correcting it or deleting it on your instruction.
7.3 If a request reaches us directly, we will forward it to you and will not respond on our own initiative.
8. Personal data breaches
8.1 If we become aware of a breach affecting data processed on your behalf, we will notify you without undue delay and provide the information you need to meet your own notification obligations under Art. 33 GDPR.
8.2 The notification will include what happened, which categories of data are affected, the likely consequences and the measures taken.
9. Your obligations
9.1 You are responsible for ensuring that you are entitled to transfer your end customers' data to us.
9.2 Please transfer only the data actually required for the order. The vehicle identification number is optional and is only needed where a vehicle-bound copy protection is requested.
9.3 Please keep your access credentials confidential and inform us without delay if you suspect unauthorised access.
10. Documentation for your own records
10.1 The data processing agreement referred to in section 5.7 of our Terms is available on request.
10.2 If you need further documentation for your own record of processing activities, contact us and we will provide what we can.
11. Contact
PowerHub
Eduard Ruder
Kaspersweg 15b
26131 Oldenburg
Germany
Telephone: +49 157 84613054, available Monday to Friday 9.00-18.00h
Email: info@powerhub.group
A data protection officer has not been appointed, as the statutory requirements for doing so are not met.