Juridische Informatie

Privacybeleid

Laatst bijgewerkt: 2 juli 2026

Soladim is een product en handelsnaam van:
Coded by Jim (Eenmanszaak)
T.a.v. Jimmy Geels
Veldhommel 37, 7423 HP Deventer, Nederland
KVK-nummer: 78095379
Btw-identificatienummer: NL003285986B44
E-mail: soladim@codedbyjim.nl

1. Definities

In dit Privacybeleid worden de volgende begrippen met een beginhoofdletter gebruikt. Deze begrippen hebben de navolgende betekenis:

  • Coded by Jim: De eenmanszaak Coded by Jim, gevestigd te Deventer en ingeschreven bij de Kamer van Koophandel onder nummer 78095379, zijnde de ontwikkelaar en eigenaar van Soladim.
  • App: De door Coded by Jim ontwikkelde mobiele applicatie genaamd 'Soladim'.
  • Systeem: De onlosmakelijke samenvoeging van de App, de eventuele bijbehorende fysieke Soladim-hardware (microcontroller/dongle) en de onderliggende software en algoritmes.
  • Gebruiker / U: De natuurlijke persoon (waaronder consumenten) of rechtspersoon die de App downloadt, installeert en/of het Systeem gebruikt.
  • Derden: Externe partijen en diensten die geen onderdeel uitmaken van Coded by Jim, zoals energieleveranciers, netbeheerders, fabrikanten van zonne-omvormers en aanbieders van (energie) API's.

2. Privacybeleid (Privacy Policy)

Coded by Jim respecteert uw privacy en treedt op als Verwerkingsverantwoordelijke. Dit privacybeleid beschrijft hoe wij omgaan met (persoons)gegevens conform de Algemene Verordening Gegevensbescherming (AVG). Het Systeem is fundamenteel gebouwd op de principes van Privacy by Design en Security by Design. Uw netwerk en uw data blijven uw eigendom.

2.1 Overzicht van Gegevensverwerkingen (Data Mapping)

Overeenkomstig de vereisten van de AVG hebben wij onze gegevensverwerkingsactiviteiten in kaart gebracht. Hieronder vindt u een gedetailleerd overzicht van de doeleinden waarvoor wij uw gegevens verwerken, de categorieën persoonsgegevens, de bijbehorende juridische grondslagen en de bewaartermijnen:

Verwerkingsdoel Categorie Persoonsgegevens Wettelijke Grondslag (Art. 6 lid 1 AVG) Retentietermijn
Energie-optimalisatie en algoritmische sturing Real-time energieverbruik, opwekgegevens zonnepanelen, status van aangesloten omvormers, Modbus-configuraties. Noodzakelijk voor de uitvoering van de overeenkomst (sub b). Uitsluitend lokaal op het apparaat. Coded by Jim ontvangt, bewaart noch verwerkt deze gegevens op een server. Data wordt gewist bij een Factory Reset.
Hardware-bestellingen en verzending Naam, afleveradres, e-mailadres, bestelgegevens. Naam en afleveradres worden gedeeld met logistieke partners (zoals PostNL of DHL) als zelfstandig verwerkingsverantwoordelijke voor de bezorging. Noodzakelijk voor de uitvoering van de overeenkomst (sub b) en wettelijke verplichting (sub c) voor de fiscale bewaarplicht. Fiscale basisgegevens (zoals factuur- en betaalgegevens) worden 7 jaar bewaard conform de wettelijke fiscale bewaarplicht. Overige contactgegevens en supportcommunicatie worden uiterlijk na 2 jaar vernietigd.
Betaalverwerking Betalingsgegevens (creditcard, iDEAL, etc.). Noodzakelijk voor de uitvoering van de overeenkomst (sub b). Coded by Jim verwerkt zelf geen betalingsgegevens. De betaling wordt volledig afgehandeld door de externe betaaldienstverlener (Mollie/Stripe), die optreedt als zelfstandig verwerkingsverantwoordelijke.
Foutrapportage, prestatietelemetrie en systeemverbetering (Sentry) Gepseudonimiseerde en zoveel mogelijk van direct identificerende kenmerken ontdaan crashrapportages, prestatiegegevens (zoals laadtijden van schermen en UI-interacties), willekeurig gegenereerd, app-specifiek installatie-ID (niet gekoppeld aan uw hardware MAC-adres of advertentie-ID). Expliciete toestemming (sub a) bij actieve opt-in. Standaard uitgeschakeld. 90 dagen in Sentry-cloud (VS), daarna automatisch verwijderd.
Technische Serverlogs (OTA-updates) IP-adres van het apparaat. Gerechtvaardigd belang (sub f): netwerkroutering, systeembeveiliging en het faciliteren en beveiligen van het OTA-downloadproces. Maximaal 30 dagen. Na deze termijn worden de logregels automatisch overschreven of permanent vernietigd. Uitgezonderd hiervan zijn geautomatiseerde en versleutelde off-site server back-ups van onze infrastructuurprovider, welke hun eigen retentiecyclus volgen en niet actief worden benaderd, evenals logs die strikt noodzakelijk zijn ter onderzoek van een lopend beveiligingsincident. Logs worden niet gekoppeld aan uw identiteit of energiegegevens.
Technische Serverlogs (Energieprijzen) IP-adres van het apparaat. Gerechtvaardigd belang (sub f): netwerkroutering, beveiliging (o.a. DDoS-bescherming) en technisch onderhoud. Maximaal 30 dagen. Na deze termijn worden de logregels automatisch overschreven of permanent vernietigd. Uitgezonderd hiervan zijn geautomatiseerde en versleutelde off-site server back-ups van onze infrastructuurprovider, welke hun eigen retentiecyclus volgen en niet actief worden benaderd, evenals logs die strikt noodzakelijk zijn ter onderzoek van een lopend beveiligingsincident. Logs worden niet gekoppeld aan uw identiteit of energiegegevens.
Klantenservice en support Naam, e-mailadres, inhoud van uw bericht. Gerechtvaardigd belang (sub f) en/of noodzakelijk voor de uitvoering van de overeenkomst (sub b). 2 jaar na het laatste contactmoment, tenzij een lopende procedure een langere bewaartermijn vereist, of zolang noodzakelijk is voor de verdediging tegen mogelijke juridische claims (tot het einde van de wettelijke verjaringstermijn van 5 jaar).

2.2 Lokale Gegevensverwerking & Hardware Beveiliging

De Soladim-architectuur is ontworpen om primair als geïsoleerde server binnen uw lokale thuisnetwerk (LAN) te opereren:

  • Geen Centrale Cloud-database: Uw energieverbruiksdata, Wi-Fi wachtwoorden (PSK), API-tokens en Modbus-configuraties worden nooit naar de servers van Coded by Jim gestuurd. Wij verzamelen of hosten deze data niet en verkopen niets aan Derden.
  • Hardware Encryptie: Alle gegevens op het fysieke Soladim-apparaat worden veilig versleuteld in het NVS-geheugen middels hardwarematige AES-XTS encryptie, via een in eFuse gebrande sleutel die de chip niet kan verlaten.
  • Wipe-on-Unlock: Het Systeem is hardwarematig ontworpen om bij het ontgrendelen van de hardware-bootloader (OEM Unlock) voor het flashen van alternatieve firmware een dwingende "Wipe-on-Unlock" uit te voeren, waarbij het de intentie en het uitgangspunt is dat alle beveiligde NVS-data permanent wordt gewist vóórdat de versleuteling wordt opgeheven.
  • Veilige App-opslag: Uw app-instellingen worden lokaal op uw smartphone versleuteld via iOS Keychain of Android Keystore. Lokale API communicatie is versleuteld via TLS 1.2+ en Trust-On-First-Use (TOFU) met behulp van de Platform Security Architecture (PSA) enclave.
  • Zelfstandige Data-export (MQTT & Integraties): De Soladim-architectuur deelt standaard géén persoons- of energiegegevens met de buitenwereld. U heeft echter de mogelijkheid om de MQTT-functionaliteit te activeren, waarmee het Systeem uw telemetrie (zoals live energieverbruik) actief doorstuurt naar een door u geconfigureerde server, clouddienst of domoticasysteem. Omdat u deze datastroom zelf initieert en de bestemming beheert, treedt u voor deze specifieke export zélf op als Verwerkingsverantwoordelijke in de zin van de AVG. Coded by Jim heeft geen controle over externe MQTT-brokers en draagt geen enkele verantwoordelijkheid of aansprakelijkheid voor de privacy, de beveiliging of eventuele datalekken die ontstaan door het (onbeveiligd) doorsturen van uw gegevens naar externe systemen.

2.3 App-Machtigingen & Systeemfuncties

De mobiele App vraagt specifieke machtigingen om met de apparatuur in uw huis te kunnen communiceren:

  • Lokaal Netwerk (mDNS/Bonsoir): Soladim vereist toegang tot het lokale netwerk om veilig en lokaal (zonder afhankelijkheid van een cloud-verbinding) te kunnen communiceren met uw zonne-omvormers en slimme P1-meter. Wij bouwen géén profielen (fingerprints) van uw lokale netwerk op.
  • Bluetooth (BLE) & Locatie: Dit wordt eenmalig gebruikt tijdens de Wi-Fi configuratie van een nieuw apparaat. Op Android implementeren wij hierbij de strikte neverForLocation vlag. Hiermee garanderen wij aan het besturingssysteem dat Bluetooth-scans uitsluitend voor apparaatdetectie zijn en dat uw fysieke GPS-locatie absoluut niet wordt opgevraagd, verzameld of gebruikt.

2.4 Foutrapportage, Telemetrie (Sentry) & Internationale Doorgifte

Om systeemstabiliteit te waarborgen en onverwachte softwarecrashes (Exceptions/Core Dumps) op te lossen, maken wij gebruik van de clouddienst Sentry. Naast foutmeldingen verzamelen wij (bij expliciete toestemming) ook prestatiegegevens (zoals laadtijden van schermen en UI-interacties) via tracing om knelpunten te identificeren en de App te verbeteren. Omdat dit netwerkverkeer naar de cloud betreft, gelden hiervoor strenge privacywaarborgen:

  • Expliciete Toestemming (Opt-in): Deze functie is standaard uitgeschakeld. Diagnostische crash- en prestatierapportages worden nooit zonder uw actieve, voorafgaande en ondubbelzinnige toestemming verzonden (Grondslag: toestemming).
  • Dataminimalisatie (Data Scrubbing): Wij hebben Sentry zodanig geconfigureerd dat IP-adressen niet structureel worden opgeslagen, en wij maken gebruik van de geautomatiseerde Data Scrubbing-mechanismen van Sentry. Hoewel Sentry is geconfigureerd om standaard geen PII (Personally Identifiable Information) te verzenden, is het wegens de aard van ongestructureerde crashlogs technisch niet 100% uit te sluiten dat incidenteel een rest-fragment (zoals een lokaal netwerk-ID in een foutmelding) wordt meegezonden, welke vervolgens door Sentry's server-side filtering verder wordt weggestreept (redacted). Er worden enkel technische stacktraces, prestatietraces en een willekeurig gegenereerd, app-specifiek installatie-ID (niet gekoppeld aan uw hardware MAC-adres of advertentie-ID) verzonden.
  • Doorgifte naar de VS & Contracten (Schrems II): Sentry verwerkt deze diagnostische data op servers in de Verenigde Staten. Sentry acteert hierbij strikt als Verwerker. Deze data-export is juridisch afgedekt onder het EU-U.S. Data Privacy Framework (DPF) en via Standard Contractual Clauses (SCC's), om een beschermingsniveau te garanderen dat gelijkwaardig is aan de Europese AVG.
  • Geen proactieve ondersteuning: Het verzamelen van diagnostische Sentry-rapportages geschiedt uitsluitend op geaggregeerd niveau ten behoeve van productverbetering en software-ontwikkeling. Het geautomatiseerd verzenden van een crashrapport creëert géén individueel support-ticket en schept geen enkele verplichting voor Coded by Jim om de fout op uw specifieke apparaat proactief te monitoren, te verhelpen of contact met u op te nemen.

2.4.1 Handmatige export van Diagnostische Gegevens en Core Dumps

Naast de geautomatiseerde Sentry-rapportages, biedt de App u de mogelijkheid om handmatig diagnostische rapporten en binaire crashbestanden ('Core Dumps') van de hardware te genereren en te delen via de deelfunctie van uw smartphone. In tegenstelling tot Sentry-rapportages worden deze bestanden niet automatisch naar Coded by Jim verzonden en vindt er geen automatische filtering (Data Scrubbing) plaats.

Wij wijzen u er nadrukkelijk op dat zowel een handmatig geëxporteerd diagnostisch rapport als een Core Dump gevoelige technische details kunnen bevatten. Een Core Dump is een onbewerkte momentopname van het werkgeheugen ten tijde van een crash en bevat ongefilterde persoonsgegevens en gevoelige informatie, waaronder onversleutelde Wi-Fi-wachtwoorden, MQTT-inloggegevens en netwerktopologie. Het diagnostische rapport bevat gedetailleerde systeem- en foutlogboeken waarin eveneens gevoelige fout- of verbindingsgegevens kunnen voorkomen. Coded by Jim ontvangt of verwerkt deze bestanden pas indien u er zelf voor kiest om deze rechtstreeks naar onze klantenservice te sturen. Door deze bestanden actief aan ons te verzenden, verleent u uitdrukkelijke toestemming (conform art. 6 lid 1 sub a AVG) voor de eenmalige verwerking van de hierin besloten (gevoelige) persoons- en netwerkgegevens, uitsluitend ten behoeve van foutanalyse. Na afhandeling van uw verzoek worden deze bestanden direct en permanent vernietigd. U behoudt te allen tijde het recht om uw toestemming in te trekken, waarna wij deze diagnostische bestanden onmiddellijk zullen vernietigen, ongeacht of uw supportverzoek reeds is afgerond. U bent er te allen tijde zelf verantwoordelijk voor om, alvorens u deze diagnostische bestanden via niet end-to-end versleutelde kanalen aan ons verzendt, eventuele in de logboeken zichtbare netwerkwachtwoorden, API-sleutels of MAC-adressen te verwijderen of te maskeren. Zodra een dergelijk bestand uw apparaat verlaat, accepteert Coded by Jim geen enkele aansprakelijkheid voor interceptie of datalekken die zich voordoen tijdens het door u geïnitieerde transport.

2.5 Geen Tracking (App Tracking Transparency)

Wij respecteren de App Tracking Transparency (ATT) richtlijnen. Wij volgen u niet over apps en websites van andere bedrijven heen. Coded by Jim deelt diagnostische gegevens nooit met advertentienetwerken, marketingpartijen of databrokers.

2.6 Algoritmische Transparantie

Het Soladim-systeem maakt gebruik van deterministische sturingsalgoritmen om de opwekking van zonnestroom en de werking van uw omvormer te optimaliseren. Omdat deze sturing direct invloed kan hebben op uw financiële besparingen en opbrengsten (bijvoorbeeld door dynamic-pricing optimalisatie), lichten wij de werking hiervan transparant toe conform de AVG:

  • Algoritmische Logica: Het algoritme analyseert continu uw real-time lokale stroomverbruik en -opwek (via de P1-meter en omvormer-Modbus) en combineert dit met de actuele dynamische energietarieven van uw leverancier. Op basis hiervan berekent het systeem of het financieel voordelig is om zonnestroom te produceren, dan wel de productie tijdelijk te dimmen of stop te zetten (bijvoorbeeld bij negatieve stroomprijzen of ter voorkoming van netbelastingsboetes).
  • Geen Persoonlijke Profilering: Het Systeem bouwt geen gedragsprofielen van u op. Het algoritme fungeert louter als geautomatiseerde en deterministische uitvoerder van de door u zelf in de App geconfigureerde wiskundige drempelwaarden (zoals de 'Zero Export Prijs'). U behoudt als gebruiker te allen tijde de volledige controle en kunt de sturing direct overschrijven (bijvoorbeeld via de "Force"-opties in de App).

Er is bij de sturing door het Systeem uitdrukkelijk geen sprake van geautomatiseerde individuele besluitvorming waaraan voor u rechtsgevolgen zijn verbonden of die u anderszins in aanmerkelijke mate treft in de zin van artikel 22 van de AVG.

2.7 Uw Rechten, Klachten & Gegevens Verwijderen

Onder de AVG heeft u recht op inzage, correctie, dataportabiliteit en verwijdering van uw persoonsgegevens. Daarnaast heeft u onder specifieke voorwaarden het recht om de verwerking van uw gegevens te beperken of hiertegen bezwaar te maken. Aangezien Coded by Jim wegens de 'Local First'-architectuur geen externe toegang heeft tot uw lokale Soladim-apparaat en uw energie- of configuratiedata nimmer op onze servers ontvangt of opslaat, roepen wij de feitelijke en technische onmogelijkheid in conform artikel 11 van de AVG. Verzoeken tot dataportabiliteit (art. 20 AVG) of gegevenswissing (art. 17 AVG) met betrekking tot deze decentrale data kunnen wij derhalve niet uitvoeren; u dient dit uitsluitend zelf te doen via de reset-functies van de hardware.

Voor persoonsgegevens die wij centraal verwerken ter afhandeling van uw bestelling (zoals uw naam, adres en bestelhistorie), kunt u uw rechten (inzage, correctie, verwijdering) uitoefenen via een e-mail naar soladim@codedbyjim.nl. Wij zullen zo snel mogelijk, maar in beginsel uiterlijk binnen één maand na ontvangst, inhoudelijk op uw verzoek reageren. Afhankelijk van de complexiteit en het aantal verzoeken kan deze termijn met twee maanden worden verlengd. Wij zullen u in dat geval binnen de eerste maand hiervan op de hoogte stellen.

Omdat Sentry-crash- en prestatierapportages gepseudonimiseerd worden verwerkt, kunnen wij individuele rapportages in onze systemen niet aan uw identiteit koppelen, tenzij u ons kunt voorzien van de specifieke, unieke identificerende Sentry-code vanuit de App (te vinden onder Instellingen > App Instellingen > Privacy & gegevens). Zonder een dergelijke identificatie is handmatige verwijdering van specifieke Sentry-data op verzoek technisch onmogelijk (art. 11 lid 2 AVG). Deze analytische data wordt echter standaard en automatisch na 90 dagen door het systeem vernietigd. U heeft te allen tijde het recht om uw eerder verleende toestemming voor Sentry-rapportages in te trekken via het menu (Instellingen > App Instellingen > Privacy & gegevens) in de App. Het intrekken van toestemming heeft geen invloed op de rechtmatigheid van de verwerking vóór de intrekking. Indien u de App van uw smartphone verwijdert alvorens u uw Sentry-ID heeft genoteerd, beroepen wij ons op de technische onmogelijkheid tot identificatie (art. 11 AVG). Uw specifieke diagnostische gegevens kunnen in dat geval niet handmatig worden geëxtraheerd, maar zullen uitsluitend de reguliere automatische retentietermijn van maximaal 90 dagen doorlopen waarna ze alsnog permanent worden vernietigd. Aangezien het Sentry-ID een pseudonieme identificator is en wij geen aanvullende persoonsgegevens verwerken om dit ID aan een specifiek persoon te koppelen (art. 11 AVG), voeren wij een verwijderverzoek gebaseerd op een verstrekt Sentry-ID direct en zonder nadere identiteitsverificatie uit. U bent er zelf verantwoordelijk voor dat u uw unieke Sentry-ID strikt vertrouwelijk houdt.

Daarnaast wijzen wij u erop dat u te allen tijde het recht heeft om een formele klacht in te dienen bij de nationale toezichthouder, de Autoriteit Persoonsgegevens (AP), indien u van mening bent dat wij uw privacyrechten schenden.

Omdat het Systeem een 'Local First'-architectuur hanteert en uitdrukkelijk geen gebruik maakt van centrale cloud-accounts of gebruikersprofielen, is er geen sprake van een account dat bij ons verwijderd dient te worden. U heeft de volledige controle over uw gegevens; het deïnstalleren van de App en het uitvoeren van een Factory Reset op de hardware verwijdert al uw gegevens definitief.

2.8 Technische Serverlogs & Cloud-infrastructuur

Omdat het Soladim-systeem lokaal in uw netwerk draait, delen wij uw data niet proactief. Voor het veilig functioneren van de hardware maakt uw apparaat op de achtergrond echter kortstondig verbinding met enkele noodzakelijke technische diensten. Hierbij wordt uw netwerk-IP-adres tijdelijk in vluchtige serverlogs verwerkt ten behoeve van netwerkrouting en beveiliging (zoals DDoS-bescherming):

  • Cloud Hosting (bijv. Microsoft Azure): Onze firmware-updates (OTA) en backend-infrastructuur worden gehost in de Europese datacenters van externe cloudproviders.
  • Energieprijzen: Om de actuele stroomprijzen op te halen, maakt het apparaat verbinding met externe data-API's. Er worden hierbij geen lokale energie- of verbruiksdata meegestuurd.
  • Kloksynchronisatie: Voor een veilige werking (o.a. het controleren van TLS-certificaten) maakt het Systeem geautomatiseerd verbinding met publieke NTP-tijdsservers (zoals pool.ntp.org of Google). Hierbij is het IP-adres van het apparaat kortstondig zichtbaar voor deze externe partijen.
  • Distributieplatforms: Indien u de App downloadt via de Apple App Store of Google Play Store, kunnen deze platforms zelfstandig geanonimiseerde analytische gegevens verzamelen over de installatie. Hierop is het privacybeleid van de desbetreffende aanbieder van toepassing; Coded by Jim heeft via haar ontwikkelaars-dashboards uitsluitend inzage in geaggregeerde, volledig geanonimiseerde statistieken die niet tot u als individu herleidbaar zijn.
  • Aangepaste Systeem-Endpoints (Custom URLs): De App biedt u de vrijheid om de standaard webadressen voor achtergronddiensten (zoals OTA-updates, energieprijzen, omvormer-templates en NTP-servers) te wijzigen naar uw eigen servers of die van derden. Indien u hiervoor kiest, zal de Soladim-hardware rechtstreeks verbinding maken met deze externe netwerken. Hierbij worden noodzakelijke technische gegevens (waaronder uw IP-adres, en bij firmware-controles mogelijk uw MAC-adres en huidige firmwareversie) evenals eventueel door u ingevulde API-sleutels naar deze door u gekozen partijen verzonden. Omdat u deze datastromen zelf omleidt, treedt u voor deze specifieke gegevensuitwisseling zelf op als Verwerkingsverantwoordelijke in de zin van de AVG. Coded by Jim heeft geen inzage in of controle over deze externe servers en accepteert geen enkele aansprakelijkheid voor de privacyrechtelijke gegevensverwerking, logging of beveiliging door deze zelfgekozen derde partijen. Indien u datastromen (zoals telemetrie of logs) bewust omleidt naar servers buiten de Europese Economische Ruimte (EER), stemt u er uitdrukkelijk mee in dat u zelfstandig verantwoordelijk bent voor de naleving van de regels omtrent de internationale doorgifte van persoonsgegevens conform Hoofdstuk V van de AVG.

Deze providers fungeren als (sub)verwerker. Waar technische data wordt verwerkt door leveranciers onder Amerikaanse wetgeving (zoals Microsoft), is deze doorgifte te allen tijde beveiligd via het EU-U.S. Data Privacy Framework (DPF) en sluiten wij Verwerkersovereenkomsten. Uitgezonderd van de standaard verwijderingstermijnen zijn geautomatiseerde en versleutelde off-site server back-ups van onze infrastructuurprovider, welke hun eigen retentiecyclus volgen en niet actief worden benaderd, evenals logs die strikt noodzakelijk zijn ter onderzoek van een lopend beveiligingsincident. Wij koppelen deze IP-adressen nooit aan uw identiteit.

2.9 Lokale Opslag (App-gegevens)

Het Systeem maakt gebruik van de lokaal beveiligde opslag van uw smartphone (zoals iOS Keychain of Android Keystore) en de hardware (NVS) om sessie-tokens, technische netwerkinstellingen, applicatievoorkeuren (zoals de gekozen weergavetaal en het donkere/lichte thema) en TLS-vingerafdrukken (TOFU) op te slaan. Omdat deze opslag strikt noodzakelijk is voor de technische werking en beveiliging van het Systeem, en uitdrukkelijk niet wordt gebruikt voor tracking of marketing, is hiervoor geen (cookie)toestemming vereist (conform art. 11.7a Telecommunicatiewet / ePrivacy Richtlijn). Voor het gebruik van cookies en vergelijkbare technieken op onze website geldt een afzonderlijke cookieverklaring, die op de website zelf wordt weergegeven.

Indien u de fysieke hardware verkoopt, overdraagt of afdankt, bent u er als eigenaar zelf voor verantwoordelijk om vooraf een 'Factory Reset' uit te voeren. Hiermee worden uw versleutelde Wi-Fi-inloggegevens, API-tokens en certificaten lokaal en permanent vernietigd. Coded by Jim is niet aansprakelijk voor datalekken of privacyschendingen die ontstaan doordat u nalaat uw persoonlijke netwerkgegevens te wissen voor de overdracht.

2.10 Minderjarigen

Onze App en het Systeem zijn niet gericht op personen jonger dan 16 jaar. Wij verzamelen niet bewust gegevens van minderjarigen.

2.11 Toegang tot Productgegevens (EU-Dataverordening)

Als gebruiker van een verbonden product heeft u op grond van de Europese Dataverordening (Verordening (EU) 2023/2854) recht op toegang tot de gegevens die door het product worden gegenereerd. Het Systeem voldoet hieraan door zijn ontwerp ('access by design'): alle door het Systeem gegenereerde energie- en configuratiegegevens zijn rechtstreeks, lokaal, kosteloos en zonder tussenkomst van Coded by Jim voor u toegankelijk via de App, en kunnen door u worden geëxporteerd of (bijvoorbeeld via MQTT) worden doorgestuurd naar een bestemming naar keuze, waaronder diensten van derden.

Legal Information

Privacy Policy

Last updated: July 2, 2026

Soladim is a product and trade name of:
Coded by Jim (Sole Proprietorship / Eenmanszaak)
Attn: Jimmy Geels
Veldhommel 37, 7423 HP Deventer, The Netherlands
Chamber of Commerce (KVK): 78095379
VAT Identification Number: NL003285986B44
Email: soladim@codedbyjim.nl

1. Definitions

In this Privacy Policy, capitalized terms shall have the following meanings:

  • Coded by Jim: The sole proprietorship Coded by Jim, registered in Deventer (The Netherlands) at the Chamber of Commerce under number 78095379, being the developer and owner of Soladim.
  • App: The mobile application named 'Soladim', developed and provided by Coded by Jim.
  • System: The combination of the App, the associated physical Soladim hardware (microcontroller/dongle), and the underlying software and algorithms.
  • User / You: The natural person (including consumers) or legal entity who downloads, installs, and/or uses the App and/or System.
  • Third Parties: External entities not affiliated with Coded by Jim, such as energy suppliers, grid operators, solar inverter manufacturers, and providers of (energy) APIs.

2. Privacy Policy

Coded by Jim acts as the Data Controller and respects your privacy. This privacy policy describes how we handle (personal) data in accordance with the European General Data Protection Regulation (GDPR). The System is fundamentally built on the principles of Privacy & Security by Design. Your network and your data remain your property.

2.1 Overview of Data Processing (Data Mapping)

In accordance with GDPR requirements, we have mapped our data processing activities. Below is a detailed overview of the purposes for which we process your data, the categories of personal data involved, the legal bases, and retention periods:

Processing Purpose Category of Personal Data Legal Basis (Art. 6(1) GDPR) Retention Period
Energy optimization and algorithmic control Real-time energy consumption, solar panel generation yield, status of connected inverters, Modbus configurations. Necessary for the performance of a contract (sub b). Local only on the device. Coded by Jim does not receive, store, or process this data on any server. Data is erased upon Factory Reset.
Hardware orders and shipping Name, delivery address, email address, order details. Name and delivery address are shared with logistics partners (e.g., PostNL or DHL) as independent data controllers for delivery purposes. Necessary for the performance of a contract (sub b) and legal obligation (sub c) for fiscal retention. Basic fiscal data (such as invoice and payment details) are retained for 7 years in accordance with statutory fiscal retention obligations. Other contact details and support communications are destroyed after a maximum of 2 years.
Payment processing Payment data (credit card, iDEAL, etc.). Necessary for the performance of a contract (sub b). Coded by Jim does not process payment data itself. Payments are handled entirely by the external payment service provider (Mollie/Stripe), acting as an independent data controller.
Crash reporting, performance telemetry, and system improvement (Sentry) Pseudonymized crash reports, stripped of directly identifying characteristics as much as possible, performance data (such as screen load times and UI interactions), and a randomly generated, app-specific installation ID (unlinked from your hardware MAC address or advertising ID). Explicit consent (sub a) upon active opt-in. Disabled by default. 90 days in Sentry cloud (US), then automatically deleted.
Technical Server Logs (OTA updates) Device IP address. Legitimate interest (sub f): network routing, system security, and facilitating and securing the OTA download process. Maximum 30 days. After this period, log entries are automatically overwritten or permanently destroyed. Excluded from this are automated and encrypted off-site server backups of our infrastructure provider, which follow their own retention cycle and are not actively accessed, as well as logs that are strictly necessary for the investigation of an ongoing security incident. Logs are not linked to your identity or energy data.
Technical Server Logs (Energy Prices) Device IP address. Legitimate interest (sub f): network routing, security (incl. DDoS protection) and technical maintenance. Maximum 30 days. After this period, log entries are automatically overwritten or permanently destroyed. Excluded from this are automated and encrypted off-site server backups of our infrastructure provider, which follow their own retention cycle and are not actively accessed, as well as logs that are strictly necessary for the investigation of an ongoing security incident. Logs are not linked to your identity or energy data.
Customer service and support Name, email address, content of your message. Legitimate interest (sub f) and/or necessary for the performance of a contract (sub b). 2 years after the last point of contact, unless an ongoing procedure requires a longer period, or for as long as necessary to defend against potential legal claims (up to the statutory limitation period of 5 years).

2.2 Local Data Processing & Hardware Security

The Soladim architecture is engineered to operate primarily as an isolated server within your Local Area Network (LAN).

  • No Central Cloud Database: Your energy consumption data, Wi-Fi passwords (PSK), API tokens, and Modbus configurations are never transmitted to our servers. We do not build profiles of you or sell data to Third Parties.
  • Hardware Encryption: All data stored on the physical Soladim device is encrypted within its NVS memory via a hardware AES-XTS key (burned into an eFuse) that cannot leave the microchip.
  • Wipe-on-Unlock: The System is designed at a hardware level to execute a mandatory "Wipe-on-Unlock" procedure when the hardware bootloader is unlocked (OEM Unlock) to install custom firmware, with the intent and principle that all private data is permanently destroyed before decryption occurs.
  • Secure App Storage: App settings are encrypted locally on your smartphone using your OS native secure storage. Local API communication is secured via TLS 1.2+ using a Trust On First Use (TOFU) model backed by the Platform Security Architecture (PSA) enclave.
  • Self-initiated Data Export (MQTT & Integrations): The Soladim architecture does not share any personal or energy data with the outside world by default. However, you have the option to activate MQTT functionality, which causes the System to actively forward your telemetry (such as live energy consumption) to a server, cloud service, or home automation system configured by you. Because you initiate this data stream yourself and control the destination, you act as the Data Controller within the meaning of the GDPR for this specific export. Coded by Jim has no control over external MQTT brokers and bears no responsibility or liability whatsoever for the privacy, security, or any data breaches arising from the (unsecured) forwarding of your data to external systems.

2.3 App Permissions & App Store Compliance

The mobile App requests specific operating system permissions purely to establish a secure local connection:

  • Local Network (mDNS/Bonsoir): Requires access to your local network to safely and locally discover and communicate with your solar inverters and smart P1-meter. We do not fingerprint or profile your network traffic.
  • Bluetooth (BLE) & Location: Used exclusively during the initial setup to transmit Wi-Fi credentials to a new device. For Android: we explicitly apply the strict neverForLocation flag. This is a technical guarantee to the OS that your physical GPS location is never requested, tracked, or used by us.

2.4 Crash Reporting, Telemetry (Sentry) & International Transfer

To ensure stability and resolve unexpected software crashes, we utilize the external cloud service Sentry. In addition to crash reports, we also collect (with your explicit consent) performance data (such as screen load times and UI interactions) via tracing to identify bottlenecks and improve the App. Because this involves network traffic to the cloud, strict privacy safeguards apply:

  • Explicit Consent (Opt-in): Diagnostic crash and performance reports are disabled by default and never sent without your active, prior, and unambiguous consent.
  • Data Minimization (Scrubbing): We have configured Sentry in such a way that IP addresses are not systematically stored, and we utilize the automated Data Scrubbing mechanisms of Sentry. Although Sentry is configured not to transmit PII (Personally Identifiable Information) by default, due to the nature of unstructured crash logs it cannot be technically 100% ruled out that an occasional residual fragment (such as a local network ID in an error message) is sent, which is subsequently redacted by Sentry's server-side filtering. Only technical data, performance traces, and a randomly generated, app-specific installation ID (unlinked from your hardware MAC address or advertising ID) are sent.
  • Data Transfer to the US & Contracts (Schrems II): Sentry processes this diagnostic data on servers in the United States, acting strictly as a Data Processor. This data transfer is legally legitimized under the EU-U.S. Data Privacy Framework (DPF) and via European approved Standard Contractual Clauses (SCCs).
  • No Proactive Support: The collection of diagnostic Sentry reports occurs solely on an aggregated level for product improvement and software development. The automated transmission of a crash report does not create an individual support ticket and creates no obligation whatsoever for Coded by Jim to proactively monitor, resolve, or contact you regarding the error on your specific device.

2.4.1 Manual Export of Diagnostic Reports and Core Dumps

In addition to automated Sentry reports, the App provides functionality to manually generate and export diagnostic reports and binary crash files ('Core Dumps') from the hardware using your smartphone's native sharing features. Unlike Sentry reports, these files are not automatically transmitted to Coded by Jim, and no automated filtering (Data Scrubbing) is applied.

We explicitly draw your attention to the fact that both a manually exported diagnostic report and a Core Dump may contain sensitive technical details. A Core Dump is a raw snapshot of the working memory at the time of a crash and may contain unfiltered personal data and sensitive information, including unencrypted Wi-Fi passwords, MQTT credentials, and network topology. The diagnostic report contains detailed system and error logs which may also contain sensitive error or connection details. Coded by Jim only receives or processes these files if you actively choose to send them directly to our customer support. By actively submitting these files to us, you grant explicit consent (in accordance with Art. 6(1)(a) GDPR) for the one-time processing of the (sensitive) personal and network data contained therein, exclusively for the purpose of error analysis. The files will be permanently destroyed immediately after your request has been resolved. You retain the right to withdraw your consent at any time, after which we will immediately destroy these diagnostic files, regardless of whether your support request has been completed. You are at all times solely responsible for removing or masking any network passwords, API keys, or MAC addresses visible in the logs before sending these diagnostic files to us via non-end-to-end encrypted channels. Once such a file leaves your device, Coded by Jim accepts no liability whatsoever for interception or data breaches occurring during the transport initiated by you.

2.5 No Tracking (App Tracking Transparency)

We respect the App Tracking Transparency (ATT) guidelines. We do not track your activity across third-party apps or websites. Coded by Jim will never share diagnostic data with advertising networks, marketers, or data brokers.

2.6 Algorithmic Transparency

The Soladim system utilizes deterministic control algorithms to optimize solar power generation and inverter behavior. Because this control directly impacts your financial savings and yields (e.g., via dynamic energy price optimization), we provide transparent information about how these decisions are made, in compliance with the GDPR:

  • Algorithmic Logic: The algorithm continuously analyzes your real-time local energy consumption and generation (via P1-meter and inverter Modbus registers) and combines this data with the current dynamic energy rates from your supplier. Based on this, the system calculates whether it is financially beneficial to generate power, or to temporarily dim or halt production (e.g., during negative electricity prices or to avoid feed-in penalties).
  • No Personal Profiling: The System does not build behavioral profiles of you. The algorithm acts purely as an automated and deterministic executor of the mathematical threshold values configured by you in the App (such as the 'Zero Export Price'). As a user, you retain full control at all times and can directly override the control (for example, via the "Force" options in the App).

The control performed by the System expressly does not involve automated individual decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 of the GDPR.

2.7 Your Rights, Complaints & Data Deletion

Under the GDPR, you have the right to access, rectify, port, and erase your personal data. Additionally, you have the right, under specific conditions, to restrict the processing of your data or to object to such processing. Since Coded by Jim, due to the 'Local First' architecture, has no external access to your local Soladim device and never receives or stores your energy or configuration data on our servers, we invoke the factual and technical impossibility in accordance with Article 11 of the GDPR. Therefore, we cannot execute requests for data portability (Art. 20 GDPR) or data erasure (Art. 17 GDPR) regarding this decentralized data; you must do this yourself exclusively via the reset functions of the hardware.

For personal data that we process centrally for the fulfilment of your order (such as your name, address, and order history), you may exercise your rights (access, rectification, erasure) by sending an email to soladim@codedbyjim.nl. We will respond to your request as soon as possible, but in principle no later than one month after receipt. Depending on the complexity and volume of requests, this period may be extended by two months. In such cases, we will inform you of the extension within the first month.

Because Sentry crash and performance reports are processed pseudonymized, we cannot link individual reports in our systems to your identity, unless you can provide us with the specific, unique identifying Sentry code from the App (found under Settings > App Settings > Privacy & data). Without such identification, manual deletion of specific Sentry data upon request is technically impossible (Art. 11(2) GDPR). This analytical data is, however, automatically and permanently destroyed by the system after 90 days. You have the right to withdraw your previously granted consent for Sentry reports at any time via the menu (Settings > App Settings > Privacy & data) in the App. The withdrawal of consent does not affect the lawfulness of the data processing prior to the withdrawal. If you remove the App from your smartphone before noting down your Sentry ID, we invoke the technical impossibility of identification (Art. 11 GDPR). In that case, your specific diagnostic data cannot be manually extracted, but will only go through the regular automatic retention period of a maximum of 90 days, after which they will still be permanently destroyed. Because the Sentry ID is a pseudonymous identifier and we do not process additional personal data to link this ID to a specific person (Art. 11 GDPR), we execute a deletion request based on a provided Sentry ID directly and without further identity verification. You are solely responsible for keeping your unique Sentry ID strictly confidential.

Furthermore, you always retain the right to lodge a formal complaint with your national supervisory authority, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), if you believe your privacy rights have been violated.

Because the System employs a 'Local First' architecture and expressly does not use central cloud accounts or user profiles, there is no account that needs to be deleted on our end. You have full control over your data; uninstalling the App and performing a Factory Reset on the hardware permanently deletes all your data.

2.8 Technical Server Logs & Cloud Infrastructure

Because the Soladim system operates locally within your network, we do not proactively share your data. However, for the secure functioning of the hardware, your device briefly connects to some necessary technical services in the background. During this process, your network IP address is temporarily processed in volatile server logs for the purposes of network routing and security (such as DDoS protection):

  • Cloud Hosting (e.g., Microsoft Azure): Our firmware updates (OTA) and backend infrastructure are hosted in the European datacenters of external cloud providers.
  • Energy Prices: To retrieve actual electricity prices, the device connects to external data APIs. No local energy or consumption data is transmitted in the process.
  • Clock Synchronization: For secure operation (including verifying TLS certificates), the System automatically connects to public NTP time servers (such as pool.ntp.org or Google). During this process, the device IP address is briefly visible to these third parties.
  • Distribution Platforms: If you download the App via the Apple App Store or Google Play Store, these platforms may independently collect anonymized analytical data regarding the installation. This is subject to the privacy policy of the respective platform provider; Coded by Jim only has access to aggregated, fully anonymized statistics via its developer dashboards, which can never be traced back to you as an individual.
  • Custom System Endpoints (Custom URLs): The App gives you the freedom to change the default web addresses for background services (such as OTA updates, energy prices, inverter templates, and NTP servers) to your own servers or those of third parties. If you choose to do so, the Soladim hardware will connect directly to these external networks. In doing so, necessary technical data (including your IP address, and for firmware checks possibly your MAC address and current firmware version) as well as any API keys you have entered will be sent to these parties chosen by you. Because you redirect these data streams yourself, you act as the Data Controller within the meaning of the GDPR for this specific data exchange. Coded by Jim has no access to or control over these external servers and accepts no liability whatsoever for the data processing, logging, or security practices of these self-chosen third parties. If you deliberately redirect data streams (such as telemetry or logs) to servers outside the European Economic Area (EEA), you explicitly agree that you are solely responsible for compliance with the regulations regarding the international transfer of personal data in accordance with Chapter V of the GDPR.

These providers act as (sub)processors. Where technical data is processed by suppliers subject to US legislation (such as Microsoft), this transfer is always secured via the EU-U.S. Data Privacy Framework (DPF) and we enter into Data Processing Agreements. Excluded from the standard deletion periods are automated and encrypted off-site server backups of our infrastructure provider, which follow their own retention cycle and are not actively accessed, as well as logs that are strictly necessary for the investigation of an ongoing security incident. We never link these IP addresses to your identity.

2.9 Local Storage (App Data)

The System uses the locally secured storage on your smartphone (such as iOS Keychain or Android Keystore) and the hardware (NVS) to store session tokens, technical network settings, application preferences (such as the chosen display language and the dark/light theme), and TLS fingerprints (TOFU). Because this storage is strictly necessary for the technical operation and security of the System, and is expressly not used for tracking or marketing purposes, no (cookie) consent is required (in accordance with Article 11.7a of the Dutch Telecommunications Act / ePrivacy Directive). The use of cookies and similar technologies on our website is covered by a separate cookie statement, which is displayed on the website itself.

If you sell, transfer, or discard the physical hardware, you as the owner are solely responsible for performing a 'Factory Reset' beforehand. This will locally and permanently destroy your encrypted Wi-Fi credentials, API tokens, and certificates. Coded by Jim is not liable for data breaches or privacy violations resulting from your failure to erase your personal network credentials prior to transfer.

2.10 Minors

Our App and the System are not directed at persons under the age of 16. We do not knowingly collect personal data from minors.

2.11 Access to Product Data (EU Data Act)

As the user of a connected product, you have the right under the European Data Act (Regulation (EU) 2023/2854) to access the data generated by the product. The System complies with this by design ('access by design'): all energy and configuration data generated by the System is directly, locally, and freely accessible to you via the App without any involvement of Coded by Jim, and can be exported by you or forwarded (for example via MQTT) to a destination of your choice, including third-party services.