Privacy Policy – myChamber Monitoring App
Memmert GmbH + Co. KG ("Memmert") takes the protection of your personal data very seriously. This Privacy Policy explains how we process data when you use the myChamber Monitoring App ("App").
Data Controller
Memmert GmbH + Co. KG
Äußere Rittersbacher Straße 38
91126 Schwabach, Germany
Phone: +49 9122 925-0
Email: [email protected]
Data Protection Officer
The following person has been appointed as data protection officer:
Mr. Stephan Hartinger
Coseco GmbH
Phone: +49 08232 80988-70
Email: [email protected]
The contact details of our Data Protection Officer are available on our website at: www.memmert.com/de/impressum/datenschutzerklaerung.
Data We Collect
When using the App, the following data may be processed:
- Account data:
- Username, email address and company name to authenticate and distinguish users and companies by the system. Contract performance (Art. 6(1)(b) GDPR)
- Company address, application and industry are collected for analysis by Memmert.
- Product data:
- Product model, serial number, (product) location, software version, error logs, system updates, user-assigned product name, sensor data, program data, device settings data of the Memmert chamber and gateway authentication token. This data is collected to the extent necessary for the provision and maintenance of the App service and the connection with the Gateway and Cloud. Contract performance
- Device & network data:
- Smartphone region, language, timezone, IP address of gateway, connection type (WLAN, Ethernet, mobile data) of gateway, error logs, parameter values. This data is processed to ensure App functionality and follow local regulations. Contract performance (Art. 6(1)(b) GDPR)
- Third-party data:
- Information from partner platforms and cookies. The App integrates third-party services (Keycloak, Google Firebase, Apple APNs, Tencent Cloud Push (TPNS), SMTP email server); these may independently collect data in accordance with their own privacy policies. Details on specific third-party tools used in the App are set out below under "Third-Party Services". Contract performance (Art. 6(1)(b) GDPR)
Purpose of Data Processing and Legal Basis
The following table sets out the specific purposes for which your data is processed, the categories of data involved, and the applicable legal basis under the GDPR:
| Purpose | Data Categories | Legal Basis |
|---|---|---|
| Providing the myChamber Monitoring App service and managing user accounts | Account data, device and product data | Contract performance (Art. 6(1)(b) GDPR) |
| Legal enforcement and protection of Memmert's rights | All relevant data categories as necessary | Legal obligation (Art. 6(1)(c) GDPR) / Legitimate interest (Art. 6(1)(f) GDPR) |
| Automatic adjustment of settings for local regulations | Smartphone region | Legal obligation (Art. 6(1)(c) GDPR) / Legitimate interest (Art. 6(1)(f) GDPR) |
Information on legitimate interest: Where we rely on legitimate interest (Art. 6(1)(f) GDPR), our interest lies in ensuring the security, stability, and continuous improvement of the App. You have the right to object to processing based on legitimate interest at any time (see "Your Rights" below).
Third-Party Services
The App may use the following third-party services. Each service may independently collect data in accordance with its own privacy policy:
1. Authentication – Keycloak
1.1 Description and Scope of Data Processing
For the management of user accounts, authentication, and session management, we use the open-source software Keycloak. Keycloak is operated by us on our own servers or on servers commissioned by us.
| Provider / Operator | Memmert GmbH + Co. KG |
|---|---|
| Server Location | EU |
| Data Processed | Email address, username, password (as cryptographic hash), session token, IP address, login timestamp, assigned roles and permissions |
| Purpose | User authentication, session management, access control |
| Legal Basis | Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in the security of our systems) |
| Retention Period | Account data is stored for the duration of the contractual relationship. Session data is deleted upon session expiry. |
| Third-Country Transfer | No – processing takes place exclusively within the EU/EEA. |
Where we use an external hosting provider for the operation of Keycloak, we have concluded a Data Processing Agreement (DPA) in accordance with Art. 28 GDPR with said provider.
2. Push Notifications (Android) – Google Firebase Cloud Messaging
2.1 Description and Scope of Data Processing
For sending push notifications to Android devices and web browsers, we use the Firebase Cloud Messaging (FCM) service provided by Google.
| Provider | Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) |
|---|---|
| Data Processed | Device token (FCM Registration Token), Instance ID, message metadata (timestamp, delivery status), operating system and app version |
| Purpose | Delivery of push notifications (e.g., regarding new messages, status changes, or security-related alerts) |
| Legal Basis | Art. 6(1)(a) GDPR (consent) – You can disable push notifications at any time in your device settings. Alternatively: Art. 6(1)(f) GDPR (legitimate interest), where notifications are necessary for the use of the service. |
| Retention Period | FCM tokens are stored as long as the app is installed on the device or until consent is withdrawn. Google deletes Instance IDs upon expiry of their validity period. |
| Third-Country Transfer | Yes – USA. The transfer is based on the EU-U.S. Data Privacy Framework (adequacy decision of the European Commission pursuant to Art. 45 GDPR) and additionally on Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. |
We have concluded a Data Processing Agreement (Data Processing Terms) with Google. For further information on data protection at Google, please refer to: https://policies.google.com/privacy
2.2 Objection and Deactivation
You can disable the receipt of push notifications at any time via your device's system settings or within the app settings. Consent already granted may be revoked at any time with effect for the future.
3. Push Notifications (iOS) – Apple Push Notification Service (APNs)
3.1 Description and Scope of Data Processing
For sending push notifications to iOS devices, we use the Apple Push Notification Service (APNs) provided by Apple.
| Provider | Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA (EU representative: Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland) |
|---|---|
| Data Processed | Device token (APNs Device Token), message metadata (timestamp, delivery status, priority), App Bundle Identifier |
| Purpose | Delivery of push notifications to iOS devices (e.g., regarding new messages, status changes, or security-related alerts) |
| Legal Basis | Art. 6(1)(a) GDPR (consent) – iOS requires explicit user consent before delivering push notifications. Alternatively: Art. 6(1)(f) GDPR (legitimate interest). |
| Retention Period | Device tokens are stored as long as the app is installed on the device or until consent is withdrawn. |
| Third-Country Transfer | Yes – USA. The transfer is based on the EU-U.S. Data Privacy Framework (adequacy decision pursuant to Art. 45 GDPR) and additionally on Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. |
For further information on data protection at Apple, please refer to: https://www.apple.com/legal/privacy/
3.2 Objection and Deactivation
You can disable push notifications at any time via the iOS system settings (Settings > Notifications) for our app.
4. Push Notifications (Android, China) – Tencent Cloud Push
4.1 Description and Scope of Data Processing
For sending push notifications to devices in the Chinese market, where Google services are not available, we use the push notification service provided by Tencent Cloud.
| Provider | Tencent Cloud Europe B.V., Buitenveldertselaan 1-5, 1082 VA Amsterdam, Netherlands (Parent company: Tencent Holdings Ltd., Cayman Islands / Shenzhen, China) |
|---|---|
| Data Processed | Device token, device identifiers, message metadata (timestamp, delivery status), operating system and app version |
| Purpose | Delivery of push notifications to users in regions where Google FCM is not available |
| Legal Basis | Art. 6(1)(a) GDPR (explicit consent) |
| Retention Period | Device tokens are stored as long as the app is installed on the device or until consent is withdrawn. |
| Third-Country Transfer | Yes – People's Republic of China. There is no adequacy decision by the European Commission for China. The transfer is based on Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. Additionally, a Transfer Impact Assessment (TIA) has been conducted in accordance with the recommendations of the European Data Protection Board (EDPB). |
We have concluded a Data Processing Agreement (DPA) with Tencent in accordance with Art. 28 GDPR.
4.2 Special Notes on Data Transfer to China
The People's Republic of China has extensive statutory government access powers (in particular under the Cybersecurity Law and the National Intelligence Law). As part of our Transfer Impact Assessment, we have implemented the following supplementary safeguards:
- Minimisation of transmitted data to the technically strictly necessary (device tokens and message metadata only – no content data)
- Encryption of data in transit (TLS)
- Contractual obligation of Tencent to disclose government access requests and to limit them to the legally required minimum
- Regular review of safeguards
4.3 Consent and Withdrawal
The use of Tencent Cloud Push is based exclusively on your explicit consent pursuant to Art. 49(1)(a) GDPR. Before granting consent, you will be informed about the risks associated with the data transfer to China. You may withdraw your consent at any time with effect for the future.
5. Email Communication – SMTP Server
5.1 Description and Scope of Data Processing
For sending transactional emails (e.g., confirmation emails, password resets, notifications), we use an SMTP email server.
| Provider | Memmert GmbH + Co. KG |
|---|---|
| Server Location | EU |
| Data Processed | Recipient's email address, name (if available), message content, sending timestamp, delivery status, mail server IP address |
| Purpose | Sending transactional emails in connection with the use of our service (e.g., account creation, email verification, password reset, notifications) |
| Legal Basis | Art. 6(1)(b) GDPR (performance of a contract) for transactional emails required for the use of the service. Art. 6(1)(a) GDPR (consent) for optional notification emails. |
| Retention Period | Sending logs are stored and subsequently deleted. |
| Third-Country Transfer | No – processing takes place exclusively within the EU/EEA. |
Where we use an external email service provider, we have concluded a Data Processing Agreement (DPA) in accordance with Art. 28 GDPR with said provider.
Data Sharing
Your data is not sold to third parties. Data may be shared with the following categories of recipients:
| Recipient / Category | Purpose | Legal Basis |
|---|---|---|
| Memmert group companies | Internal administration, service provision, support, App improvement, usage analysis, error tracking | Legitimate interest (Art. 6(1)(f) GDPR) |
| Cloud hosting / IT infrastructure provider Azure with servers in Europe | Data storage, server infrastructure, App operation | Contract performance (Art. 6(1)(b) GDPR), data processing agreement pursuant to Art. 28 GDPR. Additional guarantees: The provider is ISO 27001 and ISO 27018 certified. |
| Public authorities (where legally required) | Compliance with legal obligations | Legal obligation (Art. 6(1)(c) GDPR) |
All service providers acting as data processors are contractually bound by data processing agreements in accordance with Art. 28 GDPR. Where data is transferred to countries outside the EU/EEA, appropriate safeguards are in place (e.g., EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR or an adequacy decision pursuant to Art. 45 GDPR).
Data Retention
Personal data is stored only as long as necessary for the stated purposes or as required by law. Specifically:
- Account data: retained for the duration of your use of the App and deleted upon account deletion, unless longer retention is required by law.
- Log data (e.g., IP addresses, access logs): generally anonymized.
- Product/software data: retained if the product is registered in your account.
Statutory retention periods (e.g., under tax or commercial law) remain unaffected.
Your Rights
Under the GDPR, you have the following rights with respect to your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
- Right to lodge a complaint (Art. 77 GDPR in conjunction with § 19 BDSG)
To exercise any of your rights, please contact us using the contact details provided above.
Updates
This Privacy Policy may be updated from time to time to reflect changes in our data processing practices or legal requirements. Any material changes will be communicated to you through the App before they take effect. Continued use of the App after such notification constitutes your acceptance of the updated Privacy Policy.
Legal existence of automated decision-making (including profiling)
As a responsible company, we do not use automated decision-making or profiling in our business relationships.
Effective date: April 1, 2026