Privacy Policy
Last updated: September 2026
1. Controller
PowerHub
Eduard Ruder
Kaspersweg 15b
26131 Oldenburg
Germany
Telephone: +49 157 84613054, available Monday to Friday 9.00-18.00h
Email: info@powerhub.group
VAT identification number: DE348853710
A data protection officer has not been appointed, as the statutory requirements for doing so are not met.
2. General information
2.1 We process personal data only to the extent necessary to provide a functioning website and our services, or where a legal basis permits the processing.
2.2 Legal bases, depending on the processing in question, are Art. 6 (1) (b) GDPR for the performance of a contract and pre-contractual measures, Art. 6 (1) (c) GDPR for compliance with a legal obligation, in particular commercial and tax retention obligations, Art. 6 (1) (f) GDPR for our legitimate interests, in particular the security and stability of our systems, and Art. 6 (1) (a) GDPR where consent has been given.
2.3 Where you have given us consent, you may withdraw it at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
3. Hosting
3.1 Our portal is operated on a server provided by:
ETH-Services
Owner Lennart Seitz
Finkenweg 4
26160 Bad Zwischenahn
Germany
VAT identification number: DE362373507
3.2 The server is located in Frankfurt am Main, Germany. The provider processes personal data solely on our behalf and in accordance with our instructions. We have concluded a data processing agreement with the provider pursuant to Art. 28 GDPR.
3.3 Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest lies in a secure and efficient provision of our online offering.
3.1 Server log files
Each time our website is accessed, the following information is automatically recorded: IP address, date and time of access, the page or file accessed, referrer URL, browser type and version, operating system, and the amount of data transferred and the access status.
This data is not merged with other data sources and is used exclusively to deliver the content, to ensure system security and for troubleshooting.
Legal basis: Art. 6 (1) (f) GDPR.
Retention period: seven days, after which the data is automatically deleted.
3.2 Encryption
For security reasons, this website uses TLS encryption. An encrypted connection can be recognised by the string "https://" in your browser's address bar.
4. Fonts
The fonts used on this website are served locally from our own server. No connection to third-party servers, in particular to Google, is made. No personal data is transmitted to third parties in this connection.
5. Cookies
5.1 We use only cookies that are technically necessary for the operation of the portal, in particular to manage your login session, to protect against cross-site request forgery, and to store a display setting you have chosen yourself.
5.2 Legal basis: § 25 (2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG) and Art. 6 (1) (f) GDPR.
5.3 A consent banner is not required for this purpose. We do not use analytics, tracking or marketing cookies.
5.4 During payment, our payment service providers set additional cookies and load further components necessary to process the payment and prevent fraud. This includes the bot protection service hCaptcha, which is loaded by our payment provider Stripe at the checkout stage only. Full details, including cookie names, purposes and retention periods, are set out in our separate Cookie Policy.
6. User account and registration
6.1 Use of our portal requires the creation of a user account. We collect the following data:
Mandatory information: full name, email address, address and country, password, company name, and confirmation that you are registering as a business customer.
Optional information: a WhatsApp number for quick contact.
6.2 We require the mandatory information to establish and perform the contractual relationship and for proper invoicing. Without this information, we are unable to conclude a contract with you.
6.3 On registration you confirm that you are acting in the course of your trade, business or profession. We record this confirmation together with the date, time and the exact wording presented to you at that moment, for our own evidentiary purposes.
6.4 Passwords are stored exclusively as a cryptographic hash value and are not accessible to us in plain text.
6.5 Legal basis: Art. 6 (1) (b) GDPR; for the confirmation of business status, Art. 6 (1) (c) GDPR in connection with our obligation to correctly classify contractual relationships.
6.6 Retention period: for the duration of your account. After deletion of the account, the data is deleted unless statutory retention obligations require otherwise. Invoicing and accounting data is retained for eight or ten years pursuant to § 147 of the German Fiscal Code (AO) and § 257 of the German Commercial Code (HGB).
6.1 Verification of the VAT identification number
Where you provide a VAT identification number as a business customer, we verify it against the confirmation procedure of the German Federal Central Tax Office or the VIES system of the European Commission. This verification is currently carried out manually. We store the result for evidentiary purposes towards the tax authorities.
Legal basis: Art. 6 (1) (c) GDPR in connection with our value-added tax evidentiary obligations.
7. Order processing and uploaded files
7.1 Processing in connection with placing an order
To provide our services, we process the data you submit in the order assistant: vehicle make, model, year, engine, control unit type, the uploaded control unit file, the requested service type, and any notes you add to the order.
Optionally, you may provide a vehicle identification number (VIN). This is not required for order processing. Where you provide a VIN, it is used exclusively to generate a vehicle-bound copy protection for the file concerned. It is not linked to our internal database used for quality assurance, described in section 7.4.
Legal basis: Art. 6 (1) (b) GDPR.
Retention period: we are introducing automated deletion of orders and associated files with the following periods: six years for general business records and ten years for records subject to tax retention obligations under German law. Until this automation is in place, orders and files remain available in your account without an automatic time limit; you may request deletion of individual orders at any time.
7.2 Data of third parties, role as processor
Where you, as a business customer, transmit data relating to your own customers to us — in particular vehicle identification numbers, registration numbers or mileage — we process that data solely on your behalf and in accordance with your instructions. In relation to that data, we act as a processor within the meaning of Art. 28 GDPR. You remain the controller for that data.
Details are set out in the data processing agreement referred to in our Terms and Conditions and in our GDPR Compliance page.
You are responsible for being entitled to transmit this data to us.
7.3 Automatically supplied files
Certain services are supplied automatically from a database maintained by us. No automated decision-making within the meaning of Art. 22 GDPR that produces legal effects concerning you takes place.
7.4 Evaluation for quality assurance
We evaluate technical map and vehicle data from completed orders to improve our database and the quality of our services. This evaluation is carried out exclusively on the basis of anonymised technical data without reference to a specific person or a specific vehicle. Vehicle identification numbers are not part of this evaluation. No conclusions can be drawn about you or your customers from this data.
8. Credits and payment processing
8.1 Credits
Our services are paid for using a prepaid credit system. For each purchase and each redemption of Credits, we store the time, scope, service type and country, in order to comply with our tax record-keeping obligations.
Legal basis: Art. 6 (1) (b) and (c) GDPR.
8.2 Payment service providers
Payments are processed by the following payment service providers:
Stripe Payments Europe, Ltd.
1 Grand Canal Street Lower, Grand Canal Dock
Dublin 2, Ireland
PayPal (Europe) S.à r.l. et Cie, S.C.A.
22-24 Boulevard Royal
2449 Luxembourg
When you make a payment, the payment data you enter is transmitted directly to the payment service provider you have chosen. We never receive or store complete payment card details. We receive back only the payment status, a transaction reference and, in order to comply with our tax evidentiary obligations, the country associated with the payment method used.
Data may be transferred outside the European Union in connection with payment processing. Stripe is certified under the EU-US Data Privacy Framework; standard contractual clauses apply in addition. PayPal is established in the European Union.
During the payment process, our payment providers additionally load further components, including the bot protection service hCaptcha, and may store cookies. Details are set out in our Cookie Policy.
Legal basis: Art. 6 (1) (b) GDPR.
Privacy notices: Stripe — stripe.com/privacy; PayPal — paypal.com/privacy.
9. Accounting
For invoicing and bookkeeping, we use:
Lexware Office (cloud version)
Haufe-Lexware GmbH & Co. KG
Munzinger Straße 9
79111 Freiburg
Germany
Only the data required for invoicing is transmitted: name, address, company name where applicable, VAT identification number, invoice amounts, service type and service date. Vehicle data, vehicle identification numbers and uploaded files are not transmitted.
We have concluded a data processing agreement with the provider pursuant to Art. 28 GDPR.
Legal basis: Art. 6 (1) (c) GDPR.
10. Communication
10.1 Support system in the portal
Enquiries submitted through the support system integrated into our portal are processed and stored on our server in Frankfurt am Main. No transfer to third parties takes place.
Retention period: for the duration of your account, in line with the retention periods described in section 7.1, unless statutory retention obligations require a longer period.
10.2 Email
Our email mailbox is operated at:
united-domains GmbH
Gautinger Straße 10
82319 Starnberg
Germany
Legal basis: Art. 6 (1) (b) GDPR for contract-related communication, otherwise Art. 6 (1) (f) GDPR.
10.3 WhatsApp
You may optionally provide a WhatsApp number as an additional, voluntary means of quick contact. Providing this number is not required to use our services, which are also available in full through the support system described in section 10.1.
If you provide this number and we use it to contact you via WhatsApp, your phone number as well as the content and metadata of the communication are processed by WhatsApp Ireland Limited, Merrion Road, Ballsbridge, Dublin 4, Ireland. A transfer to the parent company Meta Platforms, Inc. in the United States may take place. Meta is certified under the EU-US Data Privacy Framework.
Legal basis: Art. 6 (1) (a) GDPR.
11. Recipients and disclosure
Your data is disclosed only to the processors and service providers named in this policy, as well as to our tax advisor to the extent required by law, and to authorities where we are legally obliged to do so.
We do not sell or rent your data.
12. Your rights
You have the right at any time to:
obtain information about the personal data we process about you (Art. 15 GDPR); request the rectification of inaccurate data (Art. 16 GDPR); request erasure (Art. 17 GDPR); request restriction of processing (Art. 18 GDPR); request data portability (Art. 20 GDPR); object to processing based on Art. 6 (1) (f) GDPR (Art. 21 GDPR); and withdraw a consent you have given at any time (Art. 7 (3) GDPR).
An informal message to the contact details given above is sufficient to exercise these rights.
Right to lodge a complaint. Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority. The competent authority for us is:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover
Germany
13. Data security
We take appropriate technical and organisational measures to protect your data against loss, destruction, manipulation and unauthorised access. These include end-to-end encrypted transmission, encrypted storage of passwords, encryption of uploaded and delivered files at file level, role-based access control, and regular automated backups. Further detail on our technical and organisational measures is available in our GDPR Compliance page.
14. Changes to this privacy policy
We reserve the right to amend this privacy policy in order to ensure it always complies with current legal requirements or to reflect changes to our services. The version current at the time of your visit applies.
Version: September 2026