End-User License Agreement — Charge Angels
Data Controller and Contact
- The entity operating the Charge Angels platform is the data controller responsible for the processing of your personal data described in this agreement.
- The Data Protection Officer is the single point of contact for every question relating to your personal data, including the exercise of all the rights listed below. Requests are answered within one month of receipt (Art. 12(3) GDPR).
Legal Basis for Each Purpose
- Contract Performance (Art. 6(1)(b) GDPR) — creating and authenticating your account, running and monitoring charging sessions, invoicing and payment, customer support, and roaming with partner networks. This processing is necessary to deliver the service you subscribed to; it does not rely on your consent and cannot be stopped without terminating your account.
- Legitimate Interest (Art. 6(1)(f) GDPR) — securing the platform (preventing fraud and automated attacks, warning you of a sign-in from a country you never used before), maintaining it, and producing aggregated statistics used to size and improve the infrastructure. You may object to this processing at any time.
- Consent (Art. 6(1)(a) GDPR) — optional notifications that are not required to run a charging session, and access to your device location. Each is requested separately, and each may be withdrawn at any time without closing your account.
- Legal Obligation (Art. 6(1)(c) GDPR) — keeping accounting and tax records, and answering requests from public authorities where the law requires it.
Purpose of Data Processing
- Provide and manage EV charging services, including session monitoring, billing, and user authentication.
- Optimize charging station usage and energy management through smart charging algorithms.
- Generate analytics and statistics on consumption, cost, and usage patterns.
- Send notifications related to charging sessions, station availability, and account activity.
- Process payments and manage billing for charging sessions.
- Enable roaming capabilities with partner networks.
Personal Data Collected
- First and last name
- Email address
- Mobile phone number
- RFID card identifiers
- Profile picture
- Postal address
- Vehicle information (license plate, VIN)
- Password (stored in hashed form only)
- Location of your device, when you allow it. The exact position is used on your device to centre the map and is stored on your device only — it never reaches our servers. The map area you are looking at is sent to our servers so that we can return the charging stations located within it.
- Camera access, when you allow it, solely to scan the QR code printed on a charging station. Images are processed on your device and are never stored or transmitted.
- IP address, and the list of countries you have already signed in from. This list is the reference against which we detect a sign-in from an unusual country; the alert we send you contains the IP address used.
- Mobile device information: operating system, application name and version, and the notification token used to deliver push messages to your device.
- Account security data: number of failed sign-in attempts, temporary blocking date, and multi-factor authentication status.
Business Data Collected
- Instant and total energy consumption
- Charging station status
- Session start/stop events
- Authorization records
- Charging curves (consumption data)
- Cost curves (pricing data)
- Session data (date, time, duration, inactivity, total consumption)
- Active sessions and session history
- Site assignment
- Registered vehicles
- Billing information
- System logs
Data Sharing and Third-Party Processors
- Depending on the features enabled on your platform, your data may be shared with the following processors, each solely for the purpose stated:
- Stripe and, where applicable, Bill24: payment processing and billing for charging sessions.
- Gireve, Hubject and other roaming partners: publishing charging station information, and exchanging the authorization tokens that let you charge on partner networks.
- Google Firebase: delivering push notifications to your mobile device.
- Google reCAPTCHA: telling human sign-in attempts from automated ones. It receives your IP address and interaction signals when you sign in.
- Google Maps and Google Places: displaying maps and completing addresses. It receives your IP address whenever a page containing a map is loaded.
- Google and Apple: authenticating you when you choose to sign in with your Google or Apple account.
- SAP Smart Charging: computing the distribution of available power across the charging stations of a site.
- SAP Concur, where your organization uses it: transferring your charging sessions into your expense reports.
- Energy and equipment operators (RTE Ecowatt, Greencom, ioThink, Lacroix, WIT): monitoring sites and electrical assets. They receive site and equipment data, not your identity.
- Your data will not be sold or shared with third parties for marketing purposes.
- Your data may be disclosed to public authorities when required by law (labor inspection, tax authorities, law enforcement).
Data Localization and International Transfers
- The application is deployed and your data is stored on cloud infrastructure located in the region indicated by the operator of this platform, who will confirm it on request to the Data Protection Officer.
- Some of the processors listed above are established in the United States (Google, Stripe). Transfers to those processors are governed either by the European Commission adequacy decision covering the EU-US Data Privacy Framework, or by the Standard Contractual Clauses adopted by the Commission. A copy of the safeguard applied to a given processor is available from the Data Protection Officer.
Data Retention
- Your account is kept for as long as you use the platform. After 6 months without a sign-in and without a charging session, your account is deactivated and you are notified. A deactivated account can no longer be used to sign in. It is permanently erased 2 months after that deactivation. Throughout those 2 months you may ask for it to be reactivated by writing to the Data Protection Officer or to an administrator: reactivation cancels the erasure.
- Your charging sessions and invoices are kept beyond the erasure of your account, because accounting and tax law require it (10 years in France). Once your account is erased they no longer carry your identity: what remains is an internal identifier that no longer matches any person.
- Technical logs are automatically deleted after 30 days, charging station communication records after 5 days, sent notifications after 5 days, and charging station outage records after 90 days.
- You may request the deletion of your account at any time, without waiting for these periods (see below).
Delete Your Account
- Via the web application:
- Log in to Charge Angels
- Edit your profile by clicking the pen button in the sidebar
- Select the ‘Miscs’ tab
- Click the red button ‘I Understand and I want to delete my account’
- Confirm the deletion
- Via the mobile application:
- Log in to the mobile app (Android / iOS)
- Go to ‘Settings’ at the bottom of the sidebar
- Click the red button ‘Delete my account’
- Confirm the deletion
- By email: send a request to the Data Protection Officer.
- Deletion removes your identity permanently: name, email address, phone number, postal address, profile picture, vehicles, badges and payment details. Your past charging sessions and the invoices attached to them remain, for the legal retention period stated above, and no longer identify you.
- Deletion cannot be completed while a charging session is still running, or while an invoice remains unpaid. In that case you are told which condition is blocking it.
Cookies and Similar Technologies
- The sign-in page loads Google reCAPTCHA, which is strictly necessary to protect the platform against automated attacks, and stores on your device only what is needed to keep you signed in and to remember your display preferences. These do not require your consent.
- Pages containing a map load Google Maps, which places its own cookies. Where the law of your country requires it, these are placed only after you have consented, and you may refuse them without losing access to any other feature.
Minors
- The platform is intended for adults. It is not designed for, and must not be used by, persons under 18. If you believe that a minor has created an account, please contact the Data Protection Officer so that it can be deleted.
Privacy by Design
- This application has been designed with personal data protection in mind from the outset, in accordance with Article 25 of the GDPR.
Security
- Authentication (username and password) is required for all users to access the application.
- All data is transmitted over the network using encrypted protocols (HTTPS), ensuring confidentiality.
- Only administrators are authorized to read, write, edit, and delete all data stored in the database.
- Standard users can only read and edit their own personal data, view charging station availability, monitor their active sessions, and access their session history and statistics.
Automated Decision-Making
- Smart charging. The platform distributes the available electrical power across the charging stations of a site. This affects the speed and the scheduling of your charge. It is a rule-based optimization, whose constraints are defined by the site operator; it is not an artificial intelligence system within the meaning of Regulation (EU) 2024/1689, and it produces neither legal effects nor similarly significant effects on you.
- Deactivation for inactivity. An account with no sign-in and no charging session for 6 months is automatically deactivated, then erased 2 months later (see ‘Data Retention’). You are notified before the deactivation and again when it takes effect. A deactivated account can no longer sign in, and only an administrator can reactivate it.
- Blocking by email domain. The operator of a platform reserved for its staff or members may automatically block the accounts whose email address no longer belongs to an authorized domain — typically after you leave the organization.
- These last two decisions restrict your access to the service. You may contest either of them, obtain a human review and state your point of view by writing to the Data Protection Officer.
Your Rights Under the GDPR
All the rights below are exercised by writing to the Data Protection Officer, who answers within one month.
Right to Withdraw Consent (Art. 7(3))
- Where a processing operation relies on your consent — optional notifications, device location — you may withdraw it at any time, either from the settings of the application, or by writing to the Data Protection Officer, without closing your account and without any consequence on the rest of the service.
- Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Right of Access (Art. 15)
- You may request access to your personal data by contacting the Data Protection Officer or an administrator, upon providing proof of identity.
Right to Rectification (Art. 16)
- You may correct most of your data directly in your profile, or request the correction of inaccurate, incomplete, or outdated personal data by contacting the Data Protection Officer.
Right to Erasure (Art. 17)
- You may request the deletion of your personal data at any time (see ‘Delete Your Account’ above), subject to the accounting retention obligation stated in ‘Data Retention’.
Right to Restrict Processing (Art. 18)
- You may request that the processing of your personal data be restricted in certain circumstances by contacting the Data Protection Officer.
Right to Data Portability (Art. 20)
- You may request the transfer of your personal data in a structured, commonly used, and machine-readable format by contacting the Data Protection Officer.
- You may also export your session data directly from the application.
Right to Object (Art. 21)
- You have the right to object to the processing of all or part of your personal data based on our legitimate interest, by contacting the Data Protection Officer.
Right to Lodge a Complaint (Art. 77)
- If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement — in France, the Commission Nationale de l'Informatique et des Libertés (CNIL).
Providing Your Data
- Your name, email address, mobile phone number and password are required to open an account: without them, the service cannot be provided. A payment method is required to start a charging session that is billed to you.
- Everything else — profile picture, postal address, vehicles — is optional, and omitting it only deprives you of the features that depend on it.
User Consent
- Accepting this agreement acknowledges that you have been informed of the processing described above.
- The processing operations that rely on your consent are subject to a separate request, and each may be refused or withdrawn without affecting your access to the service.
- This agreement may change. Any new version is presented to you before you can continue using the Charge Angels application, and the version you accepted is recorded together with its date.